Software architecture, chassis domain controller, and chassis domain system for autonomous driving

By designing the chassis controller using a centralized electronic and electrical architecture, the problems of low control precision and insufficient safety in traditional architectures are solved, enabling safe vehicle operation and efficient utilization of computing resources in fault conditions.

CN117901889BActive Publication Date: 2026-05-26CHONGQING UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHONGQING UNIV
Filing Date
2024-02-26
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Traditional distributed electronic and electrical architectures cannot meet the development requirements of intelligent chassis, resulting in low vehicle control precision, affecting operational safety, and failing to fully consider functional safety and vehicle dynamic coupling characteristics during vehicle failures.

Method used

The chassis controller adopts a centralized electronic and electrical architecture design, including an information layer, motion coordination layer, dynamics control layer, fault-tolerant control layer, and actuator control layer. By uniformly processing sensor information, it coordinates vehicle fault modes and emergency stop modes, achieving hardware and software decoupling and integrated function scheduling.

Benefits of technology

It improves vehicle control precision and operational safety, ensures safe operation in case of malfunctions, enhances the efficiency of computing resource utilization, and reduces the waste of computing resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117901889B_ABST
    Figure CN117901889B_ABST
Patent Text Reader

Abstract

This invention relates to the field of automotive autonomous driving control technology, specifically to a software architecture, chassis domain controller, and chassis domain system for autonomous driving. The information layer acquires vehicle fault commands and emergency stop commands. The motion coordination layer triggers vehicle fault modes and emergency stop modes, and acquires emergency stop control signals and longitudinal and lateral vertical control signals. The dynamics control layer acquires dynamics control target quantities based on the emergency stop control signals or longitudinal and lateral vertical control signals; the fault-tolerant control layer performs fault-tolerant control based on vehicle fault information. The actuator control layer converts the dynamics control target quantities and fault-tolerant control target quantities into actual control signals to control the actuators. This software architecture, designed from a centralized perspective, achieves decoupled development of software and hardware, centrally processes all information, and uniformly integrates and schedules functions. It comprehensively considers vehicle, driver, fault, and cross-domain interaction, improving vehicle control accuracy and operational safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive autonomous driving control technology, specifically to a software architecture, chassis domain controller, and chassis domain system for autonomous driving. Background Technology

[0002] Currently, autonomous driving technology is developing towards higher levels, and intelligent chassis have become a necessary condition for realizing high-level autonomous driving and an important carrier for various intelligent functions. However, with the increase in the number of sensors and controlled actuators, as well as the significant increase in computing power, traditional distributed electronic and electrical architectures can no longer meet the requirements of intelligent chassis development. Therefore, designing chassis controllers based on a centralized electronic and electrical architecture, using a domain-centralized and centrally-centralized approach, has become a key focus of academia and industry.

[0003] Currently, the electronic and electrical architecture of chassis controllers for autonomous vehicles suffers from three main problems: First, it fails to adequately consider how to ensure the vehicle's functional safety in the event of a malfunction; second, the inherent coupling characteristics of the vehicle's dynamics prevent unified integration and scheduling between functions, leading to mutual interference and significantly impacting the overall vehicle control performance; and third, key components are sourced from different suppliers, and the actuator control software is integrated into the components, making it difficult to fully consider actuator characteristics and achieve coordinated control across various dimensions during the control process. These three issues result in low control accuracy in existing autonomous vehicle technologies, affecting vehicle operational safety. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this invention proposes a software architecture, chassis domain controller, and chassis domain system for autonomous driving, which improves vehicle control accuracy and thus enhances vehicle operational safety.

[0005] In a first aspect, the present invention provides a software architecture for autonomous driving.

[0006] In the first possible implementation, a software architecture for autonomous driving includes:

[0007] The information layer is used to acquire sensor information; obtain vehicle state estimates and driver state data based on the sensor information; obtain emergency stop instructions based on the driver state data; and obtain vehicle fault instructions based on the vehicle state estimates.

[0008] The motion coordination layer is used to trigger the vehicle fault mode according to the vehicle fault command, trigger the emergency stop mode according to the emergency stop command, and obtain the emergency stop control signal. The motion coordination layer is also used to obtain longitudinal, lateral and vertical control signals.

[0009] The dynamics control layer is used to perform dynamics control based on emergency stop control signals or longitudinal and lateral vertical control signals, and to obtain the target dynamics control quantities.

[0010] The fault-tolerant control layer is used to perform fault-tolerant control based on vehicle fault information when a vehicle fault mode is triggered, and to obtain the fault-tolerant control target quantity.

[0011] The actuator control layer is used to obtain the actual control signal based on the dynamic control target quantity and the fault-tolerant control target quantity, and to control the actuator based on the actual control signal.

[0012] In conjunction with the first feasible approach, in the second feasible approach, the information layer includes:

[0013] The signal preprocessing unit is used to receive the signal sent by the sensor and preprocess the signal sent by the sensor to obtain sensor information;

[0014] The vehicle state estimation unit is used to estimate the sensor information and obtain the vehicle state estimate.

[0015] The vehicle fault diagnosis unit is used to determine whether the vehicle is in a fault state based on the vehicle state estimate. If the vehicle is in a fault state, it sends a vehicle fault command to the motion coordination layer.

[0016] The driver status monitoring unit is used to acquire driver status data based on sensor information, determine whether the driver has the ability to take over the vehicle based on the driver status data, and send an emergency stop command to the motion coordination layer if the driver does not have the ability to take over the vehicle.

[0017] In conjunction with the second feasible approach, the motion coordination layer in the third feasible approach includes:

[0018] The stability trajectory tracking unit is connected to the autonomous driving domain controller. The stability trajectory tracking unit is used to acquire the vehicle trajectory information of the autonomous driving domain controller and generate longitudinal, lateral and vertical control signals based on the vehicle trajectory information.

[0019] The fault mode unit is used to trigger the vehicle fault mode according to the vehicle fault command and to acquire the vehicle fault control signal.

[0020] The emergency stop unit is used to disconnect the high-level autonomous driving and advanced driver assistance commands from the autonomous driving domain controller after triggering the emergency stop mode, receive the emergency stop planning trajectory from the autonomous driving domain controller, generate an emergency stop control signal based on the emergency stop planning trajectory, and send the emergency stop control signal to the dynamics control layer.

[0021] In conjunction with the third feasible approach, the fourth feasible approach further includes the motion coordination layer:

[0022] The vehicle driving mode unit is used to configure vehicle control parameters according to driver instructions and vehicle driving modes.

[0023] The functional arbitration unit is used to prioritize various vehicle commands to be executed and output each vehicle command to be executed according to the priority order.

[0024] In conjunction with the first feasible approach, in the fifth feasible approach, the dynamics control layer performs dynamics control based on the emergency stop control signal or the longitudinal, lateral, and vertical control signals to obtain the dynamics control target quantities, including:

[0025] The desired vehicle driving status is obtained based on emergency stop control signals or longitudinal and lateral vertical control signals;

[0026] The target dynamic control quantity is calculated based on the desired vehicle driving state.

[0027] In conjunction with the first feasible approach, in the sixth feasible approach, the fault-tolerant control layer obtains the fault-tolerant control target quantity through the following methods:

[0028] Obtain the desired dynamic response of the vehicle;

[0029] Calculate the target dynamic response based on the desired dynamic response;

[0030] Construct an objective function based on the target dynamic response, and set fault constraints for the objective function based on vehicle fault information;

[0031] The objective function is solved based on the fault constraints to obtain the fault-tolerant control objective quantity.

[0032] In conjunction with the first feasible approach, in the seventh feasible approach, the actuator control layer includes an inverse model unit and a control unit. The actuator control layer calculates the dynamic control target quantity and the fault-tolerant control target quantity through the inverse model unit to obtain the actual control quantity required by each actuator. Each control unit controls each actuator based on the actual control quantity.

[0033] Secondly, the present invention provides a chassis domain controller for autonomous driving.

[0034] In the eighth possible implementation, there is a chassis domain controller for autonomous driving, which has the autonomous driving-oriented software architecture described above.

[0035] Thirdly, the present invention provides a chassis domain system for autonomous driving.

[0036] In a ninth possible implementation, a chassis domain system for autonomous driving includes multiple sensors, multiple actuators, an autonomous driving domain controller, and an autonomous driving-oriented chassis domain controller as described above, wherein each of the sensors is connected to the chassis domain controller, the autonomous driving domain controller is connected to the chassis domain controller, and the chassis domain controller is connected to each of the actuators.

[0037] As can be seen from the above technical solution, the beneficial technical effects of the present invention are as follows:

[0038] The information layer uniformly receives and processes various sensor input information. Based on the obtained sensor information, it acquires vehicle state estimates and driver state data, and then obtains vehicle fault commands and emergency stop commands. The motion coordination layer triggers the vehicle fault mode based on the vehicle fault command and the emergency stop mode based on the emergency stop command, acquires the emergency stop control signal, and acquires longitudinal, lateral, and vertical control signals. The dynamics control layer acquires the dynamics control target quantity based on the emergency stop control signal or the longitudinal, lateral, and vertical control signals. The fault-tolerant control layer performs fault-tolerant control based on the vehicle fault information when the vehicle fault mode is triggered to ensure the safe operation of the vehicle during a fault. The actuator control layer converts the received dynamics control target quantity and fault-tolerant control target quantity into actual control signals that the actuator can receive, and controls the actuator based on the actual control signals to achieve closed-loop control tracking of control quantity. This invention adopts a centralized architecture for software architecture design, realizes decoupled development of software and hardware, centrally processes all information, and integrates and schedules functions in a unified manner. It comprehensively considers the vehicle, driver, fault, and cross-domain interaction fusion, effectively improving the control accuracy and operational safety of the vehicle, and also improving the utilization efficiency of computing resources. Attached Figure Description

[0039] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the accompanying drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.

[0040] Figure 1 This embodiment provides a software architecture diagram for autonomous driving.

[0041] Figure 2 This embodiment provides a schematic diagram of the information layer logic.

[0042] Figure 3 This is a schematic diagram of the emergency parking logic provided in this embodiment;

[0043] Figure 4 This embodiment provides a schematic diagram of the reconfiguration controller allocation for a fault-tolerant control layer.

[0044] Figure 5 This is a schematic diagram of the actuator control layer logic provided in this embodiment;

[0045] Figure 6 This embodiment provides a structural schematic diagram of a chassis domain system for autonomous driving.

[0046] Figure label:

[0047] 100-Chassis Domain Controller, 110-Information Layer, 120-Motion Coordination Layer, 130-Dynamics Control Layer, 140-Fault-Tolerant Control Layer, 150-Actuator Control Layer, 200-Sensor, 300-Actuator, 400-Autonomous Driving Domain Controller. Detailed Implementation

[0048] The embodiments of the technical solution of the present invention will now be described in detail with reference to the accompanying drawings. These embodiments are merely illustrative of the technical solution of the present invention and are therefore intended to limit the scope of protection of the present invention.

[0049] It should be noted that, unless otherwise stated, the technical or scientific terms used in this application should have the ordinary meaning understood by those skilled in the art. The terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for implementation of the embodiments of this disclosure described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. Unless otherwise stated, the term "a plurality of" means two or more. In this disclosure, the character " / " indicates an "or" relationship between the preceding and following objects. For example, A / B means: A or B. The term "and / or" describes an association relationship between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or, A and B. The term "corresponding" can refer to an association or binding relationship; A corresponding to B means that there is an association or binding relationship between A and B.

[0050] Combination Figure 1As shown, this embodiment provides a software architecture for autonomous driving, including: an information layer 110 for acquiring sensor information; acquiring vehicle state estimates and driver state data based on the sensor information; acquiring emergency stop commands based on the driver state data; and acquiring vehicle fault commands based on the vehicle state estimates; a motion coordination layer 120 for triggering a vehicle fault mode based on the vehicle fault commands, triggering an emergency stop mode based on the emergency stop commands, and acquiring emergency stop control signals; the motion coordination layer is also used to acquire longitudinal and lateral vertical control signals; a dynamics control layer 130 for performing dynamics control based on the emergency stop control signals or the longitudinal and lateral vertical control signals, and acquiring dynamics control target quantities; a fault-tolerant control layer 140 for performing fault-tolerant control based on vehicle fault information when a vehicle fault mode is triggered, and acquiring fault-tolerant control target quantities; and an actuator control layer 150 for acquiring actual control signals based on the dynamics control target quantities and the fault-tolerant control target quantities, and controlling the actuators based on the actual control signals.

[0051] Combination Figure 2 As shown, optionally, the information layer 110 includes: a signal preprocessing unit, used to receive signals sent by sensors and preprocess the signals to obtain sensor information; a vehicle state estimation unit, used to estimate the sensor information to obtain a vehicle state estimation value; a vehicle fault diagnosis unit, used to determine whether the vehicle is in a fault state based on the vehicle state estimation value, and send a vehicle fault command to the motion coordination layer if the vehicle is in a fault state. The vehicle state estimation value from the vehicle state estimation unit is input to the stability trajectory tracking unit of the motion coordination layer 120. The vehicle fault diagnosis unit is connected to the fault mode unit of the motion coordination layer 120; and a driver state monitoring unit, used to acquire driver state data based on sensor information, determine whether the driver has the ability to take over the vehicle based on the driver state data, and send an emergency stop command to the motion coordination layer if the driver does not have the ability to take over the vehicle. The driver state monitoring unit is communicatively connected to the emergency stop unit of the motion coordination layer 120.

[0052] Optionally, the sensors include wheel speed frequency sensors, brake pedal opening sensors, steering wheel angle sensors, brake pressure sensors, etc. The sensors also include pressure sensors, torque sensors, and steering angle sensors installed on the actuators, and each sensor sends signals to the information layer.

[0053] Combination Figure 2As shown, optionally, the signal preprocessing unit preprocesses the signals sent by the sensors, including one or more of smoothing filtering, unit conversion, and signal conversion. The vehicle state estimation unit includes mass estimation, slope estimation, reference vehicle speed estimation, road surface adhesion coefficient estimation, and center of gravity sideslip angle estimation. In some embodiments, the signals sent by the sensors include three-dimensional acceleration, wheel speed frequency signals, and steering wheel angle signals. The signal preprocessing unit smooths and filters the three-dimensional acceleration signals from the IMU (Inertial Measurement Unit, which typically includes accelerometers, gyroscopes, and magnetometers), converts the wheel speed frequency signals to obtain actual wheel speed signals, and converts the steering wheel angle signals to front wheel angle signals according to the steering ratio. Finally, all sensor input signals are calibrated in terms of format and accuracy to reduce computational load while ensuring algorithm accuracy.

[0054] Optionally, the estimated vehicle status values ​​include vehicle mass, center of gravity sideslip angle, slope information, reference vehicle speed, motor torque, current, speed, and other vehicle status and driving condition information.

[0055] Optionally, the sideslip angle is estimated based on the vehicle's three-degree-of-freedom dynamics model using the least recursive squares method with a forgetting factor. The vehicle mass is estimated using data-driven Bi-LSTM (bidirectional long short-term memory) based on longitudinal, lateral, and vertical acceleration signals and acceleration signal differences across six dimensions. Slope information is estimated using an extended Kalman filter algorithm based on the vehicle's longitudinal dynamics model. The vehicle state estimation unit sends one or more of the calculated estimation results to the subsequent motion coordination layer as input to improve control accuracy.

[0056] Optionally, the vehicle fault diagnosis unit calculates the expected values ​​of motor torque, current, and speed under normal vehicle driving conditions using vehicle dynamics and motor models. If the difference between the expected value and the estimated value of the vehicle state is greater than the preset error range, the vehicle is judged to be faulty, the fault category is the chassis motor fault, and the fault location is the chassis motor of the vehicle.

[0057] Combination Figure 2 As shown, after preprocessing the current, voltage, vibration and other signals input from the sensors on the actuator, the vehicle fault diagnosis unit uses machine learning to predict the faults of the drive motor and steering motor based on the vehicle state estimate. When the prediction result is a fault, the vehicle is judged to be faulty, the fault type is motor fault, and the fault location is the location of the motor.

[0058] Optionally, the vehicle fault diagnosis unit includes dual fault verification. When both verifications indicate a vehicle fault, the vehicle fault is confirmed.

[0059] In some embodiments, the first fault identification method of dual fault verification involves estimating the motor torque and speed under vehicle driving conditions using vehicle dynamics and motor models, and manually setting expected values ​​under normal operating conditions. When the difference between the estimated value and the expected value of the vehicle state exceeds a preset error range, the vehicle chassis is considered faulty. The second fault identification method of dual fault verification involves using machine learning to predict drive motor and steering motor faults based on signals such as current, voltage, and vibration input from sensors on the actuators. When the prediction result indicates a fault, it is determined to be a motor fault. The fault identification results obtained from the above two methods are centrally verified. When both methods determine a fault, the vehicle fault is finally determined, along with the fault type and location.

[0060] Optionally, driver status data can be obtained by: collecting the driver's respiratory rate and heart rate data through a physiological acquisition device installed on the driver's seat, or by collecting respiratory rate and heart rate data using a respiratory monitoring wristband and a heart rate monitoring device, and by obtaining video monitoring data through an autonomous driving domain controller.

[0061] Optionally, obtaining driver status data also includes collecting pulse measurements using a pulse recorder sensor.

[0062] Optionally, determining whether a driver possesses the ability to take over the vehicle based on driver status data includes: extracting the driver's facial image from video surveillance data, and using deep learning semantic segmentation to process the eyeballs and facial expressions in the facial image to obtain the driver's current state, which may include normal, fatigued, or asleep; comparing the driver's respiratory rate and heart rate with preset standard ranges to determine whether the driver's respiratory rate and heart rate are normal. If the driver's respiratory rate and heart rate are abnormal, and the driver's current state is fatigued or asleep, it is determined that the driver does not possess the ability to take over the vehicle and there is a significant health risk, requiring immediate activation of the emergency stop mode.

[0063] In some embodiments, the standard respiratory rate range is set to 10-40, and the difference between the collected value and the standard value is set to no more than 10%; the standard heart rate range is set to 50-100, and the difference between the collected value and the standard value is set to no more than 10%. When the respiratory rate and heart rate exceed the set standard range, and the driver is currently fatigued or asleep, it is determined that the driver is not capable of taking over and that the driver is at great health risk, and the emergency stop mode is activated.

[0064] In some embodiments, the information layer serves as a module for exchanging information between the control algorithm and external sensors. It uniformly acquires and outputs information from all input chassis components, allocating this information according to the specific needs of subsequent control modules. This avoids independent information acquisition and processing by each functional module, effectively saving computational resources.

[0065] Optionally, the motion coordination layer includes: a stability trajectory tracking unit connected to the autonomous driving domain controller, which acquires vehicle trajectory information from the autonomous driving domain controller and generates longitudinal, lateral, and vertical control signals based on the vehicle trajectory information; a fault mode unit, which triggers a vehicle fault mode based on vehicle fault information; and an emergency stop unit, which, after triggering the emergency stop mode, disconnects the high-level autonomous driving and advanced driver assistance commands from the autonomous driving domain controller, receives the emergency stop planning trajectory from the autonomous driving domain controller, generates an emergency stop control signal based on the emergency stop planning trajectory, and sends the emergency stop control signal to the dynamics control layer.

[0066] In some embodiments, Figure 3 This is a schematic diagram of an emergency parking logic, combined with Figure 3 As shown, based on the information layer's assessment of the driver's takeover capability and the direct emergency stop command signal, the emergency stop unit, upon triggering, utilizes a preset self-minimum automated driving backup unit. First, it disconnects the trajectory information and advanced driver assistance commands from the high-level automated driving domain controller 400, receives the emergency stop trajectory information from the automated driving domain controller 400, and sends the emergency stop trajectory information to the trajectory tracking controller. In the kinematic coordination layer, the emergency stop trajectory information is calculated to obtain the emergency stop control signal, which includes the target steering wheel angle, target longitudinal force, target lateral force, and target vertical force, etc., and is sent to the dynamics control layer 130 to complete longitudinal, lateral, and vertical stability control. The dynamics control layer obtains the dynamic target control quantity based on the emergency stop control signal and ultimately sends the dynamic target control quantity to the actuator control layer 150 to complete tracking control, achieving safe and collision-free parking.

[0067] In some embodiments, the autonomous driving domain controller includes a high-level autonomous driving system and a high-level driving assistance system. The high-level autonomous driving system has trajectory tracking capability. When the vehicle is in autonomous driving mode, the high-level autonomous driving system in the autonomous driving domain controller obtains autonomous driving trajectory information. The stability trajectory tracking unit receives the high-level autonomous driving trajectory information from the autonomous driving domain controller, generates longitudinal, lateral, and vertical control signals based on the high-level autonomous driving trajectory information, and sends the longitudinal, lateral, and vertical control signals to the subsequent dynamics control layer.

[0068] In some embodiments, manual driving control signals are obtained by the driver operating the steering wheel, brake pedal, and accelerator pedal; emergency parking control signals are obtained by the information layer's assessment of the driver's takeover capability; and longitudinal and lateral vertical control signals are obtained based on the trajectory tracking results of the autonomous driving domain. The specific acquisition methods for the longitudinal, lateral, and vertical signals adopt the signal acquisition methods in the prior art of "Distributed Electric Drive Vehicle Longitudinal-Lateral-Vertical Force Cooperative Control".

[0069] Optionally, the motion coordination layer also includes a vehicle driving mode unit, which generates a manual driving control signal based on the driver's control instructions and sends the manual driving control signal to the subsequent dynamics control layer.

[0070] Optionally, the motion coordination layer also includes: a vehicle driving mode unit, used to configure vehicle control parameters according to driver instructions and vehicle driving mode; and a function arbitration unit, used to prioritize multiple vehicle commands to be executed and output each vehicle command to be executed according to the priority order.

[0071] Optionally, the functional arbitration unit coordinates all functions undertaken by the chassis as a whole, and arranges all received vehicle commands to be executed according to the safety level design priority. The priority order is as follows: ABS (Anti-lock Brake System) function > driver braking and steering input > advanced driver assistance system (AEB, ACC) braking commands > emergency stop > fault mode > ASR (Acceleration Slip Regulation) function > ESC (Electronic Stability Controller) function > stability trajectory tracking > advanced driver assistance system (APA).

[0072] Optionally, the vehicle driving mode unit configures vehicle control parameters based on driver instructions from the information layer and the vehicle's driving mode. Vehicle driving modes include economy driving mode, sport driving mode, and normal mode; the vehicle driving unit in the dynamics control layer assigns different control parameters to different driving modes.

[0073] In some embodiments, the motion coordination layer achieves functional coordination based on information layer judgment, mode selection, and interaction with the autonomous driving domain. It fully considers human-machine co-driving, integrates the driver's takeover capability into the chassis domain control system, and achieves cross-domain fusion between the autonomous driving domain and the chassis domain. This enhances the autonomous vehicle's ability to handle emergency situations, ensures the safety of the vehicle operation, and maximizes the vehicle's dynamic characteristics.

[0074] Optionally, the dynamics control layer performs dynamics control based on manual driving control signals, emergency stop control signals, or longitudinal and lateral vertical control signals to obtain dynamics control target quantities, including: obtaining the desired vehicle driving state based on manual driving control signals, emergency stop control signals, or longitudinal and lateral vertical control signals; and calculating the dynamics control target quantities based on the desired vehicle driving state.

[0075] Optionally, the dynamics control layer acquires dynamics control target quantities, including: converting longitudinal and lateral vertical control signals, emergency stop control signals, or manual driving control signals into the vehicle's desired driving state, which includes the total longitudinal force, total lateral force, and yaw moment of the tires; calculating the vehicle's desired driving state with the goal of minimizing the variance and average value of tire utilization rate, thereby obtaining the longitudinal force and lateral force of the vehicle's tires; calculating the longitudinal force and lateral force based on the tire model to obtain the target wheel slip ratio and sideslip angle, and calculating the vertical control target to reduce load transfer when the vehicle is turning.

[0076] In some embodiments, the calculation of the longitudinal and lateral forces of the vehicle tires, the target wheel slip ratio and sideslip angle, and the vertical control target can be performed using existing technologies, such as "Cooperative Control of Longitudinal-Transverse-Vertical Forces in Distributed Electric Drive Vehicles" (Cao Kun, Tsinghua University).

[0077] Optionally, the fault-tolerant control layer obtains the fault-tolerant control target quantity in the following ways: obtaining the desired dynamic response of the vehicle; calculating the target dynamic response based on the desired dynamic response; constructing an objective function based on the target dynamic response; setting fault constraints on the objective function based on vehicle fault information; and solving the objective function based on the fault constraints to obtain the fault-tolerant control target quantity.

[0078] Optionally, obtaining the desired dynamic response of the vehicle includes: integrating driver manipulation and wheel states to obtain the desired dynamic response, which includes the desired longitudinal vehicle speed. Lateral speed and yaw rate .

[0079] Optionally, calculating the target dynamic response based on the desired dynamic response includes: obtaining the actual dynamic response, and obtaining the target dynamic response based on the actual dynamic response and the desired dynamic response; the target dynamic response includes the total longitudinal force. Total lateral force Total yaw moment .

[0080] Optionally, the objective function can be constructed with the goal of minimizing the sum of squares of tire utilization rates as follows:

[0081] in, The coefficient of friction for each wheel on the road surface. For the longitudinal force of each wheel, Let i represent the vertical force of each wheel, where i is the number of wheels and is an integer ranging from 1 to 4.

[0082] The controller needs to satisfy the following dynamic constraints:

[0083]

[0084] In the above formula, longitudinal force, The longitudinal force on the left front wheel, The longitudinal force is on the right front wheel. The longitudinal force is on the left rear wheel. The longitudinal force is on the right rear wheel. Lateral force, The lateral force on the left front wheel. The lateral force on the right front wheel. The lateral force on the left rear wheel. The lateral force on the right rear wheel. The lateral force on the right rear wheel. This is the yaw moment.

[0085] The constraints on ground adhesion conditions are:

[0086]

[0087] Considering the torque output constraint of the motor:

[0088]

[0089] In the above formula, d is the maximum output torque of the motor, d is the wheelbase, and r is the tire radius.

[0090] Optionally, fault constraints can be introduced based on the fault constraints set in the objective function, and the vehicle's structure and parameters can be adjusted online to achieve the best control effect even under fault conditions.

[0091] When a single wheel fails, taking the left front wheel as an example, the fault constraint is as follows: .

[0092] When two motors fail, taking the failure of the left front wheel and the right rear wheel as an example, the following fault constraints are introduced:

[0093]

[0094] When three or more motors fail, apply emergency braking immediately.

[0095] When a steering motor failure occurs, residual steering capability is assessed, and residual steering and differential braking are combined to meet the total yaw moment constraint.

[0096] Optionally, the objective function is solved based on the optimization objective and fault constraints, transforming the solution into a weighted least squares problem, and solved using the standard form of the effective set, as shown below:

[0097]

[0098] In the formula, u is the control input, u = [ ], For the control quantity weight matrix, To assign weight matrices, These are the weighting coefficients. B is the reference value, B is the inequality constraint, and v is the constant coefficient vector.

[0099] Following the steps outlined above, the longitudinal and lateral forces of the target tire are obtained. Based on the tire model, these forces are calculated to determine the fault-tolerant control targets, namely the target wheel slip ratio and sideslip angle. By introducing fault constraints into the control system and adjusting its structure and parameters online, optimal control performance can still be achieved under fault conditions.

[0100] In some embodiments, combined with Figure 4 As shown, the fault mode unit sends the fault location and fault type to the motion controller in the fault-tolerant control layer. The motion controller includes allocation laws for single-wheel motor fault reconstruction controllers, opposite-side coaxial / different-axis motor fault reconstruction controllers, same-side different-axis motor fault reconstruction controllers, three-motor fault reconstruction controllers, and steering motor fault reconstruction controllers. The motion controller selects one of these allocation laws for fault-tolerant control, obtains the fault-tolerant target control quantity, and sends the fault-tolerant target controller to the actuator control layer to achieve operational control under vehicle fault conditions.

[0101] Optionally, the actuator control layer includes an inverse model unit and a control unit. The actuator control layer calculates the dynamic control target quantity and the fault-tolerant control target quantity through the inverse model unit to obtain the actual control quantity required by each actuator. Each control unit controls each actuator based on the actual control quantity.

[0102] Optionally, the actuator control layer includes inverse model units, which include inverse models of the braking system, steering system, drive system, and suspension system. Input and output data from the braking, steering, drive, or suspension systems are collected as the model's input and output. A BP neural network is then trained to obtain a high-precision and timely inverse model of the actuator. The inverse model simulates the response characteristics of the corresponding actuator system, thus interpreting the control target quantity as the actual control quantity required by each actuator system. This achieves decoupled development of software and hardware; when hardware is replaced, only the actuator inverse model needs to be replaced, reducing the difficulty of software-hardware matching and shortening the development cycle.

[0103] In some embodiments, combined with Figure 5 As shown, the inverse model unit includes inverse models of the drive system, braking system, steering system, and suspension system, and is located between the chassis domain controller architecture 100 and the actuator 300. The control unit includes a drive system controller, braking system controller, steering system controller, and suspension system controller. The actuator 300 includes a drive execution system, a braking execution system, a steering execution system, and a suspension execution system. The inputs of the drive execution system, braking execution system, steering execution system, and suspension execution system are connected to the outputs of the drive system inverse model, braking system inverse model, steering system inverse model, and suspension system inverse model, respectively. The outputs of the drive execution system, braking execution system, steering execution system, and suspension execution system are connected to the inputs of the drive system controller, braking system controller, steering system controller, and suspension system controller, respectively.

[0104] The dynamics control layer and fault-tolerant control layer input the dynamics target control quantity or capacity target control quantity into the actuator control layer. The drive system controller, braking system controller, steering system controller, and suspension system controller in the actuator control layer receive the target control quantity and input it into the inverse models of the drive system, braking system, steering system, and suspension system, respectively, to obtain the actual control quantities. These actual control quantities are then input into the actuator 300. The drive execution system, braking execution system, steering execution system, and suspension execution system in the actuator 300 perform operations according to the received actual control quantities. The actuator control layer fully considers the actuator characteristics and can quickly track the control target.

[0105] In some embodiments, a chassis domain controller for autonomous driving has the autonomous driving-oriented software architecture described above.

[0106] Combination Figure 6As shown, a chassis domain system for autonomous driving includes multiple sensors 200, multiple actuators 300, an autonomous driving domain controller 400, and a chassis domain controller 100 for autonomous driving. Each sensor 200 is connected to the chassis domain controller 100, the autonomous driving domain controller 400 is connected to the chassis domain controller 100, and the chassis domain controller 100 is connected to each actuator 300. The autonomous driving domain controller includes a high-level autonomous driving system and an advanced driver assistance system (ADAS). The high-level autonomous driving system has perception, behavioral decision-making, and trajectory tracking functions. The ADAS includes AEB (Autonomous Emergency Braking), ACC (Adaptive Cruise Control), and APA (Auto Parking Assist).

[0107] The software architecture for autonomous driving in the chassis domain controller 100 includes an information layer 110, a motion coordination layer 120, a dynamics control layer 130, a fault-tolerant control layer 140, and an actuator control layer 150. The information layer 110 includes a signal preprocessing unit, a vehicle state estimation unit, a driver state monitoring unit, and a vehicle fault diagnosis unit. The information layer 110 connects to the motion coordination layer 120, which includes a vehicle driving mode unit, a stability trajectory tracking unit, an emergency stop unit, a fault mode unit, and a function arbitration unit. The motion coordination layer 120 connects to both the dynamics control layer 130 and the fault-tolerant control layer 140. The dynamics control layer 130 is used for longitudinal, lateral, and vertical dynamics coordinated control, while the fault-tolerant control layer 140 is used for controller reconfiguration. Both the dynamics control layer 130 and the fault-tolerant control layer 140 connect to the actuator control layer 150. The actuator control layer 150 includes inverse models of the drive system, braking system, steering system, and suspension system, as well as drive system control, braking system control, steering system control, and suspension system control.

[0108] In some embodiments, combined with Figure 6 As shown, sensor 200 transmits signals to chassis domain controller 100 via hardwired connection and the vehicle's CAN network. Chassis domain controller 100 interacts with autonomous driving domain controller 400 via CAN network and Ethernet, receiving trajectory information, braking requests, and steering requests from the advanced driver assistance system (ADAS) from autonomous driving domain controller 400. Autonomous driving domain controller 400 also receives commands from chassis domain controller 100. Chassis domain controller 100 is connected to actuator 300 via hardwired connection, and actuator 300 directly receives current, voltage, and valve opening / closing commands from chassis domain controller 100. Sensors for pressure, torque, and steering angle are installed on actuator 300.

[0109] In some embodiments, the chassis domain controller architecture is applied to intelligent vehicles to ensure that the vehicle can respond quickly and correctly to commands from the autonomous driving controller and the driver. It possesses chassis self-state monitoring and management capabilities, can identify faults, and ensure the functional safety of the chassis. Through unified fusion of sensor information and unified solution of the vehicle model, computational efficiency is improved while significantly saving computational resources.

[0110] In some embodiments, the software architecture adopts a centralized control architecture with a top-down design. It unifies the processing and allocation of information from the vehicle, autonomous driving domain, and driver through an information layer, unlike traditional methods where each functional module processes information independently and repeatedly processes the same signal, effectively saving computational resources. Driver takeover capability is integrated into the chassis domain control architecture. By observing the driver's physiological characteristics, the architecture assesses the driver's takeover ability. When the driver lacks takeover capability, an emergency stop is triggered, effectively improving the safety of autonomous vehicles. The architecture fully considers the interaction and integration of multiple vehicle domains. The chassis domain software architecture considers instructions from the autonomous driving domain controller and requests an emergency stop trajectory from the autonomous driving domain during emergency stops, ensuring rational allocation of computational resources. The architecture fully considers actuator characteristics, constructing inverse models for steering, braking, drive, and suspension actuators and integrating them into the chassis domain control software architecture. This achieves hardware and software decoupling of the actuator system, ensuring that upper-layer application software is unaffected by adjustments or changes to the underlying actuators, improving vehicle control accuracy and operational safety.

[0111] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered within the scope of the claims and specification of the present invention.

Claims

1. A software architecture for autonomous driving, characterized in that, include: The information layer is used to acquire sensor information; and to obtain vehicle state estimates and driver state data based on the sensor information. Emergency stop instructions are obtained based on driver status data, and vehicle fault instructions are obtained based on vehicle status estimates. The motion coordination layer is used to trigger the vehicle fault mode according to the vehicle fault command, trigger the emergency stop mode according to the emergency stop command, and obtain the emergency stop control signal. The motion coordination layer is also used to obtain longitudinal, lateral and vertical control signals. The dynamics control layer is used to perform dynamics control based on emergency stop control signals or longitudinal and lateral vertical control signals, and to obtain the target dynamics control quantities. The fault-tolerant control layer is used to perform fault-tolerant control based on vehicle fault information when a vehicle fault mode is triggered, and to obtain the fault-tolerant control target quantity. The actuator control layer is used to obtain the actual control signal based on the dynamic control target quantity and the fault-tolerant control target quantity, and to control the actuator based on the actual control signal.

2. The software architecture for autonomous driving according to claim 1, characterized in that, The information layer includes: The signal preprocessing unit is used to receive the signal sent by the sensor and preprocess the signal sent by the sensor to obtain sensor information; The vehicle state estimation unit is used to estimate the sensor information and obtain the vehicle state estimate. The vehicle fault diagnosis unit is used to determine whether the vehicle is in a fault state based on the vehicle state estimate. If the vehicle is in a fault state, it sends a vehicle fault command to the motion coordination layer. The driver status monitoring unit is used to acquire driver status data based on sensor information, determine whether the driver has the ability to take over the vehicle based on the driver status data, and send an emergency stop command to the motion coordination layer if the driver does not have the ability to take over the vehicle.

3. The software architecture for autonomous driving according to claim 2, characterized in that, The motion coordination layer includes: The stability trajectory tracking unit is connected to the autonomous driving domain controller. The stability trajectory tracking unit is used to acquire the vehicle trajectory information of the autonomous driving domain controller and generate longitudinal, lateral and vertical control signals based on the vehicle trajectory information. The fault mode unit is used to trigger the vehicle fault mode according to the vehicle fault command and to acquire the vehicle fault control signal. The emergency stop unit is used to disconnect the high-level autonomous driving and advanced driver assistance commands from the autonomous driving domain controller after triggering the emergency stop mode, receive the emergency stop planning trajectory from the autonomous driving domain controller, generate an emergency stop control signal based on the emergency stop planning trajectory, and send the emergency stop control signal to the dynamics control layer.

4. The software architecture for autonomous driving according to claim 3, characterized in that, The motor coordination layer also includes: The vehicle driving mode unit is used to configure vehicle control parameters according to driver instructions and vehicle driving modes. The functional arbitration unit is used to prioritize various vehicle commands to be executed and output each vehicle command to be executed according to the priority order.

5. The software architecture for autonomous driving according to claim 1, characterized in that, The dynamics control layer performs dynamics control based on emergency stop control signals or longitudinal, lateral, and vertical control signals to obtain dynamics control target quantities, including: The desired vehicle driving status is obtained based on emergency stop control signals or longitudinal and lateral vertical control signals; The target dynamic control quantity is calculated based on the desired vehicle driving state.

6. The software architecture for autonomous driving according to claim 1, characterized in that, The fault-tolerant control layer obtains the fault-tolerant control target quantity in the following ways: Obtain the desired dynamic response of the vehicle; Calculate the target dynamic response based on the desired dynamic response; Construct an objective function based on the target dynamic response, and set fault constraints for the objective function based on vehicle fault information; The objective function is solved based on the fault constraints to obtain the fault-tolerant control objective quantity.

7. The software architecture for autonomous driving according to claim 1, characterized in that, The actuator control layer includes an inverse model unit and a control unit. The actuator control layer calculates the dynamic control target quantity and the fault-tolerant control target quantity through the inverse model unit to obtain the actual control quantity required by each actuator. Each control unit controls each actuator based on the actual control quantity.

8. A chassis domain controller for autonomous driving, characterized in that, The chassis domain controller has a software architecture for autonomous driving as described in any one of claims 1 to 7.

9. A chassis domain system for autonomous driving, characterized in that, It includes multiple sensors, multiple actuators, an autonomous driving domain controller, and a chassis domain controller for autonomous driving as described in claim 8, wherein each of the sensors is connected to the chassis domain controller, the autonomous driving domain controller is connected to the chassis domain controller, and the chassis domain controller is connected to each of the actuators.