Software updating method of autonomous vehicle, server and autonomous vehicle
By creating software update tasks, obtaining vehicle status information and batch updates, the problem of inefficient software updates of autonomous driving vehicles is solved, and safe and efficient software updates are achieved.
Patent Information
- Application Number
- CN202311625053.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-05-30
AI Technical Summary
The existing software update method for autonomous driving vehicles requires manual operation, resulting in inefficiency and possible update omissions or traffic accidents.
By creating multiple software update tasks, obtaining vehicle status information of autonomous driving vehicles, determining whether they meet the software update conditions, including being in a safe state, and batch updating vehicle software.
The batch update of autonomous driving vehicle software has been realized, the update efficiency has been improved, the vehicle is in a safe state before update, and the risk of traffic accidents has been reduced.
Smart Images

Figure CN120066535A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of autonomous driving, and more particularly, to a software update method, a server, and an autonomous driving vehicle for an autonomous driving vehicle. Background Art
[0002] With the gradual popularization of autonomous driving technology, higher requirements are put forward for the operation and management of autonomous driving vehicles. Especially in terms of software updates for autonomous driving vehicles, that is, in the case of high-risk software and hardware version defects, security vulnerabilities, or potential traffic accident hazards during the driving process of autonomous driving vehicles, software updates are often carried out by manually operating the autonomous driving vehicles. For example, manually clicking to confirm the installation vehicle by vehicle, manually controlling the autonomous driving vehicles to be updated to stop vehicle by vehicle, etc. Summary of the Invention
[0003] According to a first aspect of the present disclosure, there is provided a software update method for an autonomous driving vehicle, including:
[0004] Creating a plurality of software update tasks, where the plurality of software update tasks correspond to a plurality of autonomous driving vehicles one by one; the software update task is a task of updating the software used by the autonomous driving vehicle to a first software;
[0005] Obtaining vehicle state information of the autonomous driving vehicle according to the software update task for the autonomous driving vehicle;
[0006] Determining whether the autonomous driving vehicle meets set software update conditions according to the vehicle state information; where the software update conditions include that the autonomous driving vehicle is in a safe state;
[0007] When the autonomous driving vehicle meets the software update conditions, batch-updating the software used by the autonomous driving vehicle from a second software to the first software; where the first software and the second software are software of different versions.
[0008] Optionally, the determining whether the autonomous driving vehicle is in a safe state according to the vehicle state information includes:
[0009] Determining that the autonomous driving vehicle is in a safe state when the vehicle state information indicates that components of the autonomous driving vehicle are free of faults and the autonomous driving vehicle is in a safe area.
[0010] Optionally, the components of the autonomous driving vehicle include at least one of an action component, a control component, a communication component, and a signal acquisition component.
[0011] Optionally, the safety area includes at least one of a parking lot for setting an autonomous vehicle and a designated parking area.
[0012] Optionally, after determining whether the autonomous vehicle meets the set software update conditions according to the vehicle state information, the method further includes:
[0013] In the case where the autonomous vehicle does not meet the software update conditions, notifying an operator to perform safety processing on the autonomous vehicle; wherein the safety processing includes at least one of remotely controlling the autonomous vehicle to be in a safety area and repairing components of the autonomous vehicle.
[0014] Optionally, in the case where the autonomous vehicle meets the software update conditions, batch-updating the software used by the autonomous vehicle from a second software to the first software includes:
[0015] In the case where the autonomous vehicle meets the software update conditions, sending a software update instruction to the autonomous vehicle; wherein the software update instruction is used to trigger the autonomous vehicle to re-check whether it meets the software update conditions;
[0016] In the case where the re-check result indicates that the autonomous vehicle meets the software update conditions, batch-updating the software used by the autonomous vehicle from a second software to the first software.
[0017] Optionally, after sending the software update instruction to the autonomous vehicle, the method further includes:
[0018] In the case where the re-check result indicates that the autonomous vehicle does not meet the software update conditions, re-determining whether the autonomous vehicle meets the software update conditions; in the case where it is re-determined that the autonomous vehicle meets the software update conditions, sending the software update instruction to the autonomous vehicle again.
[0019] Optionally, after creating a plurality of software update tasks, the method further includes:
[0020] According to the number of the plurality of software update tasks, creating a corresponding number of state machines to parallelly start the plurality of software update tasks;
[0021] After starting the plurality of software update tasks, obtaining the vehicle state information of the autonomous vehicle according to the software update task for the autonomous vehicle.
[0022] According to a second aspect of the present disclosure, there is provided a server, including:
[0023] A creation module, configured to create a plurality of software update tasks; wherein, the plurality of software update tasks correspond to a plurality of autonomous vehicles one by one, and the software update task is a task of updating the software used by the autonomous vehicle to a first software.
[0024] An acquisition module, configured to acquire the vehicle state information of the autonomous vehicle according to the software update task for the autonomous vehicle.
[0025] A determination module, configured to determine whether the autonomous vehicle meets the set software update conditions according to the vehicle state information; wherein, the software update conditions include that the autonomous vehicle is in a safe state.
[0026] An update module, configured to batch update the software used by the autonomous vehicle from a second software to the first software when the autonomous vehicle meets the software update conditions; wherein, the first software and the second software are software of different versions.
[0027] According to a third aspect of the present disclosure, an autonomous vehicle is provided, including a memory and a processor, the memory is configured to store a computer program, and the processor is configured to execute the method steps performed by the autonomous vehicle according to any one of the first aspect under the control of the computer program.
[0028] According to the method of the embodiments of the present disclosure, by creating a plurality of software update tasks, wherein the plurality of software update tasks correspond to a plurality of autonomous vehicles one by one, and the software update task is a task of updating the software used by the autonomous vehicle to a first software; acquiring the vehicle state information of the autonomous vehicle according to the software update task for the autonomous vehicle; determining whether the autonomous vehicle meets the set software update conditions according to the vehicle state information; wherein, the software update conditions include that the autonomous vehicle is in a safe state; when the autonomous vehicle meets the software update conditions, batch updating the software used by the autonomous vehicle from a second software to the first software; wherein, the first software and the second software are software of different versions. It is possible to batch update the software used by the autonomous vehicles, and before the software update, determine whether the autonomous vehicle is in a safe state. When the autonomous vehicle is in a safe state, update the software of the autonomous vehicle to the first software, which can improve the safety of the autonomous vehicle during the software update process, and, when it is determined that the autonomous vehicle is in a safe state, directly start the software update without manual confirmation of the update, which can improve the efficiency of the software update.
[0029] Other features and advantages of the present invention will become clear through the following detailed description of the exemplary embodiments of the present invention with reference to the accompanying drawings. Description of the Drawings
[0030] The drawings incorporated in and forming a part of this specification illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention.
[0031] Figure 1 is a schematic structural diagram of an autonomous driving system capable of implementing an autonomous driving vehicle software update method according to an embodiment of the present invention;
[0032] Figure 2 is a schematic flowchart of an autonomous driving vehicle software update method according to an embodiment;
[0033] Figure 3 is a schematic flowchart of an autonomous driving vehicle software update method according to an example;
[0034] Figure 4 is a schematic flowchart of an autonomous driving vehicle software update method according to another embodiment;
[0035] Figure 5 is a schematic interaction flowchart of an autonomous driving vehicle software update method according to an embodiment;
[0036] Figure 6 is a block schematic diagram of a server according to an embodiment;
[0037] Figure 7 is a block schematic diagram of an autonomous driving vehicle according to an embodiment;
[0038] Figure 8 is a block schematic diagram of an electronic device according to an embodiment. Detailed Description of the Invention
[0039] Various exemplary embodiments of the present invention will now be described in detail with reference to the drawings. It should be noted that: Unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions and values set forth in these embodiments do not limit the scope of the present invention.
[0040] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.
[0041] Techniques, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the techniques, methods, and devices should be considered as part of the specification.
[0042] In all examples shown and discussed herein, any specific values should be construed as merely exemplary and not as limitations. Thus, other examples of the exemplary embodiments may have different values.
[0043] It should be noted that like reference numerals and letters refer to like items in the following figures, and thus, once an item is defined in one figure, further discussion thereof is not required in subsequent figures.
[0044] <Hardware Configuration>
[0045] Figure 1 is a schematic structural diagram of an autonomous driving system that can be used to implement the embodiments of the present disclosure.
[0046] As Figure 1 shown, the autonomous driving system 1000 may include a server 1100, an autonomous driving vehicle 1200, a client 1300, and a network 1400.
[0047] The server 1100 is a computer that provides processing, database, and communication facilities. The server 1100 can be an integrated server or a distributed server across multiple computers or computer data centers. The server can be of various types, for example, but not limited to, a web server, a news server, a mail server, a messaging server, an advertising server, a file server, an application server, an interactive server, a database server, or a proxy server. In some embodiments, each server may include hardware, software, or embedded logic components for performing the appropriate functions supported or implemented by the server, or a combination of two or more such components. For example, the server such as a blade server, a cloud server, a rack server, etc., or may be a server group composed of multiple servers, and may include one or more of the above types of servers, etc.
[0048] In one example, the server 1100 may be as Figure 1 shown, and may include a processor 1100, a memory 1200, an interface device 1300, a communication device 1400, a display device 1500, and an input device 1600. Although the server may also include a speaker, a microphone, etc., these components are reasonably irrelevant to the present invention and are thus omitted here.
[0049] Among them, the processor 1100 may be, for example, a central processing unit CPU, a microcontroller unit MCU, etc. The memory 1200 may include, for example, a ROM (read-only memory), a RAM (random access memory), a non-volatile memory such as a hard disk, etc. The interface device 1300 may include, for example, a USB interface, a serial interface, an infrared interface, etc. The communication device 1400 can perform wired or wireless communication, for example. The display device 1150 may be, for example, a liquid crystal display screen, an LED display screen, a touch display screen, etc. The input device 1160 may include, for example, a touch screen, a keyboard, etc.
[0050] In the embodiments of the present disclosure, the memory 1120 of the server 1100 is used to store instructions for controlling the operation of the processor 1110 to support the implementation of the methods executed by the server in any embodiment of the present disclosure. Those skilled in the art can design the instructions according to the solutions disclosed in the present disclosure. How the instructions control the operation of the processor is well known in the art, so it will not be described in detail herein.
[0051] In this embodiment, the server 1100 may already store a configuration file of the first software, and the configuration file includes information such as the version number, check value, and download address of the first software.
[0052] Those skilled in the art should understand that although Figure 1 shows multiple devices of the server 1100, the server 1100 in the embodiments of the present disclosure may only involve some of the devices, for example, only involve the processor 1110 and the memory 1120.
[0053] The autonomous vehicle 1200 may be a vehicle with various power modes such as an electric vehicle, a hybrid vehicle, and a fuel vehicle.
[0054] As Figure 1 shown, the autonomous vehicle 1200 may include a processor 1210, a memory 1220, an interface device 1230, a communication device 1240, a display device 1250, an input device 1260, a positioning device 1270, an audio device 1280, and so on. The processor 1210 may be a central processing unit CPU, a microprocessor MCU, etc. The memory 1220 includes, for example, a ROM (read-only memory), a RAM (random access memory), a non-volatile memory such as a hard disk, etc. The interface device 1230 includes, for example, a USB interface, a headphone interface, etc. The communication device 1240 can perform wired or wireless communication, for example. The display device 1250 is, for example, a liquid crystal display screen, a touch display screen, etc. The input device 1260 may include, for example, a touch screen, a keyboard, etc. The autonomous vehicle 1200 can be positioned through the positioning device 1270 and report the position information to the server 1100 through the communication device 1240. The autonomous vehicle 1200 can output audio information through the audio device 1280 and / or pick up the voice information input by the user. The audio device 1280 includes, for example, a speaker and / or a microphone.
[0055] The autonomous vehicle 1200 can be a vehicle capable of autonomous driving. In the embodiments of the present disclosure, the memory 1220 of the autonomous vehicle 1200 is used to store instructions for controlling the operation of the processor 1210 to support the implementation of the method executed by the autonomous vehicle according to any embodiment of the present disclosure. Those skilled in the art can design the instructions according to the solutions disclosed in the present disclosure. How the instructions control the operation of the processor is well known in the art and will not be described in detail herein.
[0056] Those skilled in the art should understand that although multiple devices of the autonomous vehicle 1200 are shown in Figure 1 , the autonomous vehicle 1200 in the embodiments of the present disclosure may only involve some of the devices, for example, only involve the processor 1210, the memory 1220, the communication device 1240, the positioning device 1270, etc.
[0057] As Figure 1 shown, the client 1300 may include a processor 1310, a memory 1320, an interface device 1330, a communication device 1340, a display device 1350, an input device 1360, a positioning device 1370, an audio device 1380, and so on. The processor 1310 may be a central processing unit CPU, a microprocessor MCU, etc. The memory 1320 includes, for example, ROM (read-only memory), RAM (random access memory), non-volatile memory such as a hard disk, etc. The interface device 1330 includes, for example, a USB interface, a headphone interface, etc. The communication device 1340 can perform wired or wireless communication, for example. The display device 1350 is, for example, a liquid crystal display screen, a touch display screen, etc. The input device 1360 may include, for example, a touch screen, a keyboard, etc. The client 1300 can be positioned through the positioning device 1370 and report the location information to the server 1100 through the communication device 1340. The client 1300 can output audio information through the audio device 1380 and / or pick up the voice information input by the user. The audio device 1380 includes, for example, a speaker and / or a microphone.
[0058] The client 1300 can be a terminal device used by a user, such as a smartphone, a portable computer, a desktop computer, a tablet computer, or any device that can support receiving orders.
[0059] In the embodiments of the present disclosure, the memory 1320 of the client 1300 is used to store instructions for controlling the operation of the processor 1310 to support the implementation of the method executed by the client according to any embodiment of the present disclosure. Those skilled in the art can design the instructions according to the solutions disclosed in the present disclosure. How the instructions control the operation of the processor is well known in the art and will not be described in detail herein.
[0060] Those skilled in the art should understand that although inFigure 1 Multiple devices of the client 1300 are shown, however, the terminal device 1300 of the embodiments of the present disclosure may only involve some of the devices, for example, only involve the processor 1310, the memory 1320, the communication device 1340, the display device 1350, etc.
[0061] The network 1400 can be a wireless communication network or a wired communication network, and can be a local area network or a wide area network. In Figure 1 In the shown autonomous driving system, the autonomous driving vehicle 1200 and the server 1100, the client 1300 and the server 1100 can all communicate through the network 1400. In addition, the network 1400 based on which the autonomous driving vehicle 1200 communicates with the server 1100 and the client 1300 communicates with the server 1100 can be the same or different.
[0062] It should be understood that although Figure 1 only one server 1100, autonomous driving vehicle 1200 and client 1300 are shown, it does not mean restricting the corresponding numbers. The autonomous driving system 1100 may include multiple servers 1100, autonomous driving vehicles 1200 and clients 1300.
[0063] In the process of operating and managing multiple autonomous driving vehicles, it may be necessary to update the software used by the autonomous driving vehicles due to problems such as high-risk software and hardware version defects, security vulnerabilities, and potential traffic accident hazards during the driving process of the autonomous driving vehicles, or due to changes in the market demand for autonomous driving vehicles and technological updates and iterations. However, in the related art, software updates are often performed by manually operating the autonomous driving vehicles one by one, for example, manually controlling each vehicle to stop, manually clicking to download and install for each vehicle, etc., resulting in low efficiency of software updates. Moreover, in scenarios where there is a severe shortage of manpower and there are many autonomous driving vehicles that need software updates, there may be situations such as omissions in the update of autonomous driving vehicles or other serious traffic accidents.
[0064] Based on this, the present application provides a software update solution for autonomous driving vehicles, which can achieve batch software updates for autonomous driving vehicles, and the software update process does not require manual participation, improving the efficiency of software updates for autonomous driving vehicles.
[0065] <Method Embodiment 1>
[0066] Figure 2 is a schematic flowchart of a software update method for an autonomous driving vehicle according to an embodiment. The method of this embodiment is implemented by the server. Below, taking Figure 1 the server 1100 in
[0067] According to Figure 2 As shown, the software update method for autonomous driving vehicles in this embodiment may include the following steps S2100 to S2400:
[0068] Step S2100, create multiple software update tasks.
[0069] In this embodiment, during the operation and management of multiple autonomous driving vehicles, the server 1100 may create software update tasks for the autonomous driving vehicles according to the user feedback on the usage experience, the discovery of vulnerabilities in the software used by the autonomous driving vehicles themselves, the high-risk events that occur to the autonomous driving vehicles, the changes in market demands, etc. Those skilled in the art should understand that the basis for the server 1100 to create software update tasks is not limited here.
[0070] In one embodiment, the server 1100 may create a software update task upon receiving the first feedback information regarding a high-risk event that occurs during the driving of an autonomous driving vehicle.
[0071] In this embodiment, during the autonomous driving process, if a high-risk event occurs to an autonomous driving vehicle, for example, events with relatively high potential traffic accident hazards such as brake operation failure and excessive turning amplitude, the autonomous driving vehicle or the client of the user using the autonomous driving vehicle sends the first feedback information regarding the high-risk event to the server. When the server receives the first feedback information, it detects the autonomous driving vehicle to determine whether there is a fault in the software used by the autonomous driving vehicle. In the case of a software fault in the autonomous driving vehicle, a software update task is created to update the faulty software to a relatively safe software.
[0072] During the operation and management of multiple autonomous driving vehicles by the server 1100, regardless of the reason for the software update of the autonomous driving vehicle, the autonomous driving vehicles involved are not limited to one autonomous driving vehicle. Therefore, multiple software update tasks can be created, and each software update task corresponds to the software update of an autonomous driving vehicle, and the software versions used by the autonomous driving vehicles participating in the software update are the same. For example, the software versions used by the multiple autonomous driving vehicles are all the second software.
[0073] In one example, when a high-risk event occurs to a certain autonomous driving vehicle during the autonomous driving process, the server 1100 may create a task for software updating multiple autonomous driving vehicles according to the first feedback information regarding the high-risk event sent by the autonomous driving vehicle through the human-computer interaction interface configured by the server 1100.
[0074] After the server creates multiple software update tasks, it enters the software update state, which can be, for example, a state where the server cannot normally provide autonomous driving support for the autonomous vehicle.
[0075] The software update task can be a task of updating the software used by the autonomous vehicle to the first software. Among them, the software participating in the update can be all the software for autonomous driving or part of the software for autonomous driving. For example, positioning software, perception software, prediction software, planning software, control software, etc. There is no limitation here.
[0076] The software update can be software upgrade, software rollback, etc. There is no limitation here. Due to different types of software updates, the first software is also different. In the example corresponding to software upgrade, the first software corresponds to the newly developed software. In the example corresponding to software rollback, the first software corresponds to the safe historical version software.
[0077] Step S2200, the server 1100 obtains the vehicle state information of the autonomous vehicle according to the software update task for the autonomous vehicle.
[0078] In this embodiment, after creating multiple software update tasks, the server obtains the vehicle state information according to the autonomous vehicles corresponding to the multiple software update tasks.
[0079] The autonomous vehicle is provided with multiple cameras and sensors to collect vehicle state information and send it to the server. Among them, the vehicle state information can include the state information of the autonomous vehicle itself and the state information of the surrounding environment of the autonomous vehicle. The state information of the autonomous vehicle itself can be, for example, vehicle speed information, vehicle gear information, vehicle component information, etc., and the surrounding environment information of the autonomous vehicle can be, for example, the location where the autonomous vehicle is located, the direction in which the autonomous vehicle is traveling, etc.
[0080] Step S2300, determine whether the autonomous vehicle meets the set software update conditions according to the vehicle state information.
[0081] In one embodiment, the software update conditions include that the autonomous vehicle is in a safe state. The determining whether the autonomous vehicle is in a safe state according to the vehicle state information includes:
[0082] When the vehicle state information indicates that the components of the autonomous vehicle are fault-free, it is determined that the autonomous vehicle is in a safe state.
[0083] In this embodiment, the software update conditions include that the autonomous vehicle is in a safe state. The safe state corresponds to the state where the components of the autonomous vehicle are fault-free.
[0084] In one embodiment, the components of the autonomous vehicle include at least one of an action component, a control component, a communication component, and a signal acquisition component.
[0085] In this embodiment, the autonomous vehicle includes four categories of components: The first category of components is the action component, such as a steering component, a braking component, an acceleration component, etc. This category of components can perform corresponding actions based on action instructions. The second category of components is the control component, that is, the "brain" of the autonomous vehicle, similar to the role of a driver, which can control the action component to act by sending action instructions to the action component. The third category of components is the communication component, such as a gateway, which can communicate with the server 1100, for example, upload vehicle status information to the server 1100 and receive the configuration file of the first software sent by the server 1100. The fourth category of components is the signal acquisition component, which includes multiple cameras and sensors, such as ultrasonic sensors, etc., which can acquire vehicle status information, send the vehicle status information to the control component, or send the vehicle status information to the server 1100 through the communication component.
[0086] In this embodiment, when the vehicle status information indicates that the components of the autonomous vehicle are fault-free, it is determined that the autonomous vehicle is in a safe state. Among them, the components of the autonomous vehicle being fault-free can mean that at least one category of the above four categories of components is fault-free, or that all four categories of components are fault-free, which is not limited here.
[0087] In another embodiment, the software update condition includes that the autonomous vehicle is in a safe state. Determining whether the autonomous vehicle is in a safe state according to the vehicle status information includes:
[0088] When the vehicle status information indicates that the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle is in a safe state.
[0089] In this embodiment, the software update condition includes that the autonomous vehicle is in a safe state. The safe state corresponds to the state where the autonomous vehicle is in a safe area.
[0090] In one embodiment, the safe area includes at least one of a set parking lot for the autonomous vehicle and a demarcated parking area.
[0091] In this embodiment, the safe area can be a dedicated parking lot set by the operator for the autonomous vehicle to park the autonomous vehicle. The safe area can also be a demarcated parking area by the roadside. The safe area can also be the parking lot of the autonomous vehicle and the demarcated parking area by the roadside, which is not limited here.
[0092] In this embodiment, when the vehicle status information indicates that the autonomous vehicle is in a safe area, it shows that the potential for a traffic accident of the autonomous vehicle is relatively small. At this time, it is determined that the autonomous vehicle is in a safe state.
[0093] In another embodiment, the software update condition includes that the autonomous vehicle is in a safe state. Determining whether the autonomous vehicle is in a safe state according to the vehicle status information includes:
[0094] When the vehicle status information indicates that the components of the autonomous vehicle are fault-free and the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle is in a safe state.
[0095] In this embodiment, the software update condition includes that the autonomous vehicle is in a safe state, and the safe state corresponds to the state where the components of the autonomous vehicle are fault-free and the autonomous vehicle is in a safe area.
[0096] In one embodiment, the software update condition includes that the autonomous vehicle is in a parked state and a safe state. Determining whether the autonomous vehicle is in a parked state and a safe state according to the vehicle status information includes:
[0097] When the vehicle status information indicates that the vehicle speed of the autonomous vehicle is zero and / or the autonomous vehicle is in the parking gear, and the components of the autonomous vehicle are fault-free and / or the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle is in a parked state and a safe state.
[0098] In this embodiment, the software update condition includes that the autonomous vehicle is in a parked state and a safe state, that is, when the autonomous vehicle is in a parked state and a safe state, it is determined that the autonomous vehicle meets the set software update conditions. Among them, the parked state can correspond to the state where the vehicle speed of the autonomous vehicle is zero and / or the gear of the autonomous vehicle is in the parking gear, and the safe state can correspond to the state where the components of the autonomous vehicle are fault-free and / or the autonomous vehicle is in a safe area.
[0099] In one example, when the vehicle status information indicates that the vehicle speed of the autonomous vehicle is zero and the components of the autonomous vehicle are fault-free, it is determined that the autonomous vehicle is in a safe state and a parked state.
[0100] In another example, when the vehicle status information indicates that the autonomous vehicle is in the parking gear and the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle is in a parked state and a safe state.
[0101] In yet another example, when the vehicle status information indicates that the speed of the autonomous vehicle is zero, the components of the autonomous vehicle are fault-free, and the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle is in a safe state and a parked state.
[0102] In yet another example, when the vehicle status information indicates that the autonomous vehicle is in park gear, the components of the autonomous vehicle are fault-free, and the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle is in a parked state and a safe state.
[0103] It should be noted that after the server obtains the vehicle status information, it can simultaneously determine whether the autonomous vehicle is in a parked state and a safe state, or it can first determine whether the autonomous vehicle is in a parked state. After determining that the autonomous vehicle is in a parked state, it can then determine whether the autonomous vehicle is in a safe state. There is no limitation here.
[0104] Step S2400, when the autonomous vehicle meets the software update condition, batch update the software used by the autonomous vehicle from the second software to the first software.
[0105] Exemplarily, the server 1100 creates 40 software update tasks, and each software update task corresponds to an autonomous vehicle. The server determines that 30 vehicles meet the software update condition based on the vehicle status information of the autonomous vehicle corresponding to each software update task, and then updates the software used by these 30 autonomous vehicles from the second software to the first software.
[0106] In this embodiment, the second software can be all the software for autonomous driving or part of the software for autonomous driving. There is no limitation here.
[0107] In the example of creating a software update task corresponding to a high-risk event, the second software can be the software related to the high-risk event. For example, when the high-risk event is a steering failure, the second software can be the software related to steering.
[0108] The second software and the first software can be different versions of the software.
[0109] In the example where the software update is an upgrade of the second software, the version number of the first software is higher than that of the second software. The configuration file of the first software can be stored in the server 1100. The server 1100 can send the configuration file of the first software and the start software update instruction to the autonomous vehicle when the autonomous vehicle meets the software update condition, so that the autonomous vehicle can download and install them, thereby completing the software update.
[0110] In the example where the software update is a rollback of the second software, the version number of the first software is lower than the version number of the second software, the first software is safe software, and the second software is faulty software. Server 1100 can detect whether the autonomous driving vehicle stores a configuration file of the first software when the autonomous driving vehicle meets the software update conditions. In the case where the autonomous driving vehicle stores a configuration file of the first software, server 1100 sends a start software update instruction to the autonomous driving vehicle to control the autonomous driving vehicle to roll back the second software to the first software. In the case where the autonomous driving vehicle does not store a configuration file of the first software, server 1100 sends the configuration file of the first software and an instruction to start the software update to the autonomous driving vehicle so that the autonomous driving vehicle can download and install it.
[0111] In the related art, when updating the software used by the autonomous driving vehicle, it is necessary to manually click on each vehicle to confirm the download and installation, and it is impossible to automatically update the software used by the autonomous driving vehicle from the second software to the first software. In this application, when the server determines that the autonomous driving vehicle meets the software update conditions, it can automatically update the software used by the autonomous driving vehicle from the second software to the first software. Moreover, when multiple autonomous driving vehicles meet the software update conditions, the multiple autonomous driving vehicles can be controlled to update the software at the same time, thereby updating the software used by the autonomous driving vehicles from the second software to the first software in batches.
[0112] In one embodiment, in step S2400, when the autonomous driving vehicle meets the software update condition, batch updating the software used by the autonomous driving vehicles from the second software to the first software includes: steps S2411 to S2412.
[0113] Step S2411, when the autonomous driving vehicle meets the software update conditions, sending a software update instruction to the autonomous driving vehicle; wherein the software update instruction is used to trigger the autonomous driving vehicle to retest whether it meets the software update conditions.
[0114] In this embodiment, when the server 1100 determines that the autonomous driving vehicle meets the software update conditions, it sends a software update instruction to the autonomous driving vehicle. When the autonomous driving vehicle receives the software update instruction, it retests whether it meets the software update conditions, that is, the autonomous driving vehicle retests whether it meets the software update conditions through the vehicle status information it collects.
[0115] In an embodiment where the corresponding software update condition includes the autonomous driving vehicle being in a safe state, the autonomous driving vehicle can determine whether the components of the autonomous driving vehicle are fault-free and whether the autonomous driving vehicle is in a safe area through the collected vehicle status information, and further determine whether the autonomous driving vehicle is in a safe state.
[0116] In an embodiment where the corresponding software update conditions include that the autonomous vehicle is in a safe state and a parked state, the autonomous vehicle can determine whether the autonomous vehicle is in a park gear based on the collected vehicle state information, whether the components of the autonomous vehicle are fault-free, and whether the autonomous vehicle is in a safe area, and then determine whether the autonomous vehicle is in a safe state and a parked state.
[0117] Those skilled in the art should understand that the way the autonomous vehicle rechecks whether it meets the software update conditions is basically the same as the way the server determines whether the autonomous vehicle meets the software update conditions. The exemplary description here for the autonomous vehicle to recheck whether it meets the software update conditions cannot be used as a limitation to this application.
[0118] Step S2412, when the recheck result indicates that the autonomous vehicle meets the software update conditions, batch update the software used by the autonomous vehicle from the second software to the first software.
[0119] In an embodiment, after sending the software update instruction to the autonomous vehicle in step S2411, the method further includes: step S2413 and step S2414.
[0120] Step S2413, when the recheck result indicates that the autonomous vehicle does not meet the software update conditions, re-determine whether the autonomous vehicle meets the software update conditions.
[0121] In this embodiment, when the recheck result indicates that the autonomous vehicle does not meet the software update conditions, the autonomous vehicle sends a second feedback message to the server.
[0122] In an example, the second feedback message may carry the recheck items of the autonomous vehicle and the corresponding results of the recheck items.
[0123] In an embodiment where the corresponding software update conditions include that the autonomous vehicle is in a safe state, the recheck items may include the components of the autonomous vehicle and the parking position of the autonomous vehicle. When it is rechecked that the autonomous vehicle does not meet the software update conditions, the second feedback message may include at least one of the component failure of the autonomous vehicle and the autonomous vehicle not being in a safe area.
[0124] In this embodiment, when the server receives the second feedback message, it executes step S2200 and step S2300 again to re-determine whether the autonomous vehicle meets the software update conditions. Step S2200 and step S2300 have been described in detail above and will not be elaborated here.
[0125] Step S2414, when it is re-determined that the autonomous driving vehicle meets the software update conditions, the software update instruction is sent to the autonomous driving vehicle again.
[0126] In this embodiment, when the server re-determines that the autonomous driving vehicle meets the software update conditions, it once again sends a software update instruction to the autonomous driving vehicle to trigger the autonomous driving vehicle to retest whether it meets the software update conditions. When the result of the retest indicates that the autonomous driving vehicle meets the software update conditions, the software used by the autonomous driving vehicle is updated from the second software to the first software. When the result of the retest indicates that the autonomous driving vehicle does not meet the software update conditions, the server continues to re-determine whether the autonomous driving vehicle meets the software update conditions. This cycle is repeated until the server and the autonomous driving vehicle both determine that the autonomous driving vehicle meets the software update conditions, that is, when the server's test results and the autonomous driving vehicle's retest results both indicate that the autonomous driving vehicle meets the software update conditions, the software used by the autonomous driving vehicle is updated.
[0127] According to an embodiment of the present application, when the server determines that the autonomous driving vehicle meets the software update conditions, the server sends a software update instruction to the autonomous driving vehicle to trigger the autonomous driving vehicle to retest whether it meets the software update instruction. When the server and the autonomous driving vehicle both determine that the autonomous driving vehicle meets the software update instruction, the software used by the autonomous driving vehicle is updated, which can further improve the security of the autonomous driving vehicle software update.
[0128] In one embodiment, the software update condition includes that the autonomous driving vehicle is in a safe state. After determining whether the autonomous driving vehicle meets the set software update condition based on the vehicle status information in step S2300, the method further includes: step S3100.
[0129] Step S3100, when the autonomous driving vehicle does not meet the software update conditions, notify the operating personnel to perform safety processing on the autonomous driving vehicle; wherein the safety processing includes at least one of remotely controlling the autonomous driving vehicle to be in a safe area and repairing the fault of the autonomous driving vehicle component.
[0130] In this embodiment, when the server determines that the autonomous driving vehicle does not meet the software update conditions, the server notifies the operator to perform safety processing on the autonomous driving vehicle. The software update conditions include that the autonomous driving vehicle is in a safe state, and the safe state corresponds to at least one of the components of the autonomous driving vehicle being fault-free and the autonomous driving vehicle being in a safe area. Correspondingly, the autonomous driving vehicle not meeting the software update conditions may be at least one of the components of the autonomous driving vehicle being faulty and the autonomous driving vehicle not being in a safe area.
[0131] In an example where it is determined that the autonomous driving vehicle does not meet the software update condition because the autonomous driving vehicle is not in a safe area, the position information and the autonomous driving vehicle identification information of the autonomous driving vehicle are sent to the terminal of the operator, so that the operator can perform safety processing on the autonomous driving vehicle, that is, remotely control the autonomous driving vehicle to move to a safe area according to the position information and the autonomous driving vehicle identification information.
[0132] In an example where it is determined that the autonomous driving vehicle does not meet the software update condition due to a component failure of the autonomous driving vehicle, the position information and the autonomous driving vehicle identification information of the autonomous driving vehicle can be sent to the terminal of the operator, so that the operator can perform safety processing on the autonomous driving vehicle, that is, repair the components of the autonomous driving vehicle.
[0133] In an example where it is determined that the autonomous driving vehicle does not meet the software update condition due to a component failure of the autonomous driving vehicle and the autonomous driving vehicle is not in a safe area, the operator cannot remotely control the autonomous driving vehicle to drive. At this time, the position and identification information of the autonomous driving vehicle, as well as the fault information of the components of the autonomous driving vehicle, can be sent to the terminal of the operator, so that the operator can prepare corresponding fault handling tools according to the fault information, and go to repair the components of the autonomous driving vehicle according to the position and identification information of the autonomous driving vehicle. After the repair is completed, the autonomous driving vehicle can be controlled near-field or remotely to move to a safe area.
[0134] In one embodiment, the software update condition further includes that the autonomous driving vehicle is in a parked state. After determining whether the autonomous driving vehicle meets the set software update condition according to the vehicle state information in step S2300, the method further includes: step S3200.
[0135] Step S3200, in the case where the autonomous driving vehicle is not in a parked state, send a parking prompt message instructing the driver to stop to the autonomous driving vehicle.
[0136] In this embodiment, when the server 1100 determines that the autonomous driving vehicle is not in a parked state, it sends a parking prompt message instructing the driver to stop to the autonomous driving vehicle to prompt the driver to operate to stop the autonomous driving vehicle. The parking prompt message can be, for example: "There is a safety risk for the autonomous driving vehicle, please pull over" or "There are high-risk safety hazards for the autonomous driving vehicle, please park the vehicle in the parking lot".
[0137] In one example, the server 1100 may include a cloud control scheduling system and cloud control. The cloud control can be used for manual remote real-time control of an autonomous vehicle. Since the number of cloud control operators is limited, the cloud control scheduling system is required to allocate cloud control for the autonomous vehicle. When the server 1100 determines that the autonomous vehicle is not in a parked state, it queues up to access the cloud control through the cloud control scheduling system. When the cloud control is accessed, the driver operates the autonomous vehicle, and the cloud control sends a parking prompt message instructing the driver to stop to the autonomous vehicle. After receiving the parking prompt message, the driver can select a safe area to park according to the current surrounding environment.
[0138] According to the method of the embodiment of the present application, by sending a parking prompt message instructing the driver to stop to the autonomous vehicle when the autonomous vehicle is not in a parked state, the safety of the autonomous vehicle can be improved.
[0139] In one embodiment, the step of batch-updating the software used by the autonomous vehicle from the second software to the first software in step S2400 includes: batch-updating the software used by the autonomous vehicle from the second software to the first software through an over-the-air (OTA) system.
[0140] In this embodiment, the server 1100 includes an over-the-air (OTA) system, abbreviated as the OTA system. The OTA system in the server 1100 can control the software of the autonomous vehicle to be updated from the second software to the first software through a wireless network.
[0141] In an example where the configuration file of the first software is not stored in the corresponding autonomous vehicle, the OTA system can control the autonomous vehicle to download and install the first software. When the configuration file of the first software is stored in the corresponding autonomous vehicle, the OTA system can control the autonomous vehicle to install the first software. Those skilled in the art should understand that the OTA system can also perform various item validations during the software update process. For example, it validates the integrity of the first software, etc. When the validation result shows that the first software is complete, the second software is updated to the first software, which is not limited herein.
[0142] In one embodiment, after creating multiple software update tasks in step S2100, the method further includes: step S3300, creating state machines corresponding to the number of the software update tasks and starting the multiple software update tasks in parallel. After starting the multiple software update tasks, step S2200 is executed to obtain the vehicle state information of the autonomous vehicle according to the software update task for the autonomous vehicle.
[0143] In one example, when the number of software update tasks is 3, that is, the number of autonomous driving vehicles participating in the software update is 3, state machines corresponding to each autonomous driving vehicle are created in 3 threads for the 3 autonomous driving vehicles to start the three software update tasks in parallel. After the three software update tasks are started, the vehicle state information of the autonomous driving vehicles corresponding to the three software update tasks is obtained.
[0144] In one embodiment, after creating state machines corresponding to the corresponding number to start the multiple software update tasks in parallel, the method further includes: step S3400, displaying the progress of the multiple software update tasks.
[0145] Continuing with the above example, after creating 3 state machines to start three software update tasks in parallel, the human-machine interface configured by the server can display the progress of the three state machines. For example, the progress of the first software update task is to determine whether the vehicle state information meets the software update conditions, the progress of the second software update task is that the software of the autonomous driving vehicle is being updated from the second software to the first software, and the progress of the third software update task is that the software update has been completed.
[0146] In one embodiment, after step S2400 batch-updates the software used by the autonomous driving vehicle from the second software to the first software, the method further includes:
[0147] Step S3500, after the multiple software update tasks end, restore the operating state.
[0148] In this embodiment, after the multiple software update tasks end, the server restores the operating state and can provide autonomous driving support for the autonomous driving vehicles.
[0149] According to the above steps S2100 to S2400, for the method of this embodiment, according to the method of an embodiment of the present disclosure, by creating a plurality of software update tasks, wherein the plurality of software update tasks correspond to a plurality of autonomous driving vehicles one by one, and the software update task is a task of updating the software used by the autonomous driving vehicle to a first software; according to the software update task for the autonomous driving vehicle, obtaining the vehicle status information of the autonomous driving vehicle; according to the vehicle status information, determining whether the autonomous driving vehicle meets the set software update conditions; wherein, the software update conditions include that the autonomous driving vehicle is in a safe state; when the autonomous driving vehicle meets the software update conditions, batch-updating the software used by the autonomous driving vehicle from a second software to the first software; wherein, the first software and the second software are software of different versions. It is possible to achieve batch-updating of the software used by autonomous driving vehicles, and before software update, determine whether the autonomous driving vehicle is in a safe state. When the autonomous driving vehicle is in a safe state, update the software of the autonomous driving vehicle to the first software, which can improve the safety of the autonomous driving vehicle during the software update process. Also, when it is determined that the autonomous driving vehicle is in a safe state, directly start the software update without manual confirmation of the update, which can improve the efficiency of the software update.
[0150] <Example>
[0151] Figure 3 is a flowchart of a software update method for an autonomous driving vehicle according to another embodiment, implemented by the server 1100, as Figure 3 shown, the software update method for the autonomous driving vehicle includes steps S1 to S9.
[0152] Step S1, create a plurality of software update tasks.
[0153] In this embodiment, the software update tasks can be created through the human-machine interaction interface configured by the server 1100.
[0154] Step S2, according to the number of software update tasks, create state machines corresponding to the number and start a plurality of software update tasks in parallel.
[0155] Step S3, according to the autonomous driving vehicle corresponding to the software update task, obtain the vehicle status information.
[0156] Step S4, whether the vehicle status information indicates that the vehicle speed of the vehicle is zero and / or the vehicle is in the parking gear; if so, execute step S5, if not, execute step S6.
[0157] Step S5, whether the vehicle status information indicates that the components of the vehicle are free of faults and the vehicle is in a safe area; if so, execute step S7. If not, execute step S8.
[0158] In one example, the components of the autonomous driving vehicle include at least one of an action component, a control component, a communication component, and a signal acquisition component.
[0159] In one example, the safety area includes at least one of a parking lot and a designated parking area for setting up an autonomous vehicle.
[0160] In another example, the above step S4 and step S5 may be performed simultaneously, or step S5 may be performed first and then step S4, which is not limited here.
[0161] Step S6, sending a parking prompt message to the autonomous driving vehicle to instruct the driver to stop, and continuously executing steps S3 and S4 until it is determined that the autonomous driving vehicle is in a parking state.
[0162] Step S7, sending a software update instruction to the autonomous driving vehicle.
[0163] In this embodiment, after receiving the software update instruction, the autonomous driving vehicle obtains the vehicle status information, retests whether it meets the software update conditions, and sends the retest results to the server.
[0164] Step S8, notify the operating personnel to perform safety handling on the autonomous driving vehicle, and continue to execute steps S3 to S5 until it is determined that the autonomous driving vehicle is in a safe state.
[0165] In this embodiment, the safety processing may include at least one of remotely controlling the autonomous driving vehicle to be in a safe area and repairing the components of the autonomous driving vehicle.
[0166] Step S9, whether the second feedback information is received; if not, execute step S10, if so, return to step S3.
[0167] In this embodiment, the second feedback information is sent to the server when the autonomous driving vehicle determines that it does not meet the software update conditions after retesting. If the server does not receive the second feedback information, it means that the retest result of the autonomous driving vehicle is that it meets the software update conditions. If the server receives the second feedback information, it means that the retest result of the autonomous driving vehicle is that it does not meet the software update conditions, and it is necessary to return to step S3, and the server re-determines whether the autonomous driving vehicle meets the software update conditions.
[0168] Step S10, updating the software used by the autonomous driving vehicles from the second software to the first software in batches through an over-the-air download system.
[0169] In some examples, the server 1100 may display the progress of the multiple software update tasks after creating a corresponding number of state machines in step S2 to start the multiple software update tasks in parallel.
[0170] In this embodiment, the progress of multiple software update tasks can be displayed through the human-machine interaction interface configured by the server 1100.
[0171] Step S11, after multiple software update tasks are completed, resume the operating state.
[0172] In this embodiment, after creating multiple software update tasks, the server enters the software update state. For example, the software update state can correspond to stopping providing autonomous driving support for the autonomous vehicle. After the multiple software update tasks are completed, the operating state is resumed to provide autonomous driving support for the autonomous vehicle.
[0173] <Method Embodiment Two>
[0174] Figure 4 It is a flowchart of a software update method for an autonomous vehicle according to an embodiment. In one embodiment, the method can be implemented by an autonomous vehicle. In one example, the autonomous vehicle can be Figure 1 the autonomous vehicle 1200 shown in
[0175] According to Figure 4 shown, the software update method for the autonomous vehicle in this embodiment may also include the following steps S4100 to S4300:
[0176] Step S4100, when a high-risk event occurs during the driving of the autonomous vehicle, send a first feedback message about the high-risk event to the server; wherein, the first feedback message triggers the server to create multiple software update tasks, and the multiple software update tasks are tasks for updating the software used by the autonomous vehicle to the first software.
[0177] In this embodiment, the high-risk event can be an event with a relatively high potential for traffic accidents. For example, the brake failure of the autonomous vehicle, the excessive steering amplitude of the autonomous vehicle, etc. When a high-risk event occurs during the driving of the autonomous vehicle, a first feedback message about the high-risk event is sent to the server. Among them, the first feedback message can include specific information about the high-risk event, such as the type and occurrence frequency of the high-risk event. When the server receives the first feedback message, it detects whether the software of the autonomous vehicle is faulty. When the software of the autonomous vehicle is faulty, multiple software update tasks for updating the software used by the autonomous vehicle to the first software are created. Each software update task corresponds to an autonomous vehicle, and the software used by the multiple autonomous vehicles participating in the multiple software update tasks is the same.
[0178] Software update can be a software upgrade or a software rollback. Correspondingly, the first software can be a newly developed high-version software or a historically used version of software, which is not limited here.
[0179] When the server has created a software update task for the autonomous driving vehicle, it sends an information acquisition request to the autonomous driving vehicle.
[0180] In step S4200, the autonomous driving vehicle sends vehicle status information of the autonomous driving vehicle to the server according to the information acquisition request sent by the server, so that the server can determine whether the autonomous driving vehicle meets the set software update conditions based on the vehicle status information.
[0181] In this embodiment, the autonomous driving vehicle is provided with a plurality of cameras and sensors, such as a binocular camera and an ultrasonic sensor, to obtain vehicle status information. The vehicle status information includes information corresponding to the autonomous driving vehicle itself and information corresponding to the environment in which the autonomous driving vehicle is located.
[0182] The autonomous driving vehicle obtains the information in response to the request and sends the vehicle status information to the server so that the server can determine whether the autonomous driving vehicle meets the software update conditions.
[0183] In one embodiment, the software update conditions include a security status.
[0184] In this embodiment, the safety status may correspond to the status information of the autonomous driving vehicle indicating that the components of the autonomous driving vehicle are fault-free and the autonomous driving vehicle is in a safe area.
[0185] In another embodiment, the software update condition includes a parking state and a safety state.
[0186] Step S4300, receiving the software update instruction sent by the server when it is determined that the autonomous driving vehicle meets the software update conditions.
[0187] In this embodiment, when the server determines that the autonomous driving vehicle meets the software update conditions, it sends a software update instruction to the autonomous driving vehicle.
[0188] Step S4400: Retest whether the autonomous driving vehicle meets the software update conditions according to the software update instruction.
[0189] In this embodiment, when the autonomous driving vehicle receives the software update instruction, it retests whether it meets the software update conditions. Specifically, the autonomous driving vehicle obtains vehicle status information and determines whether the autonomous driving vehicle meets the software update conditions based on the vehicle status information.
[0190] In an example where the corresponding software update condition includes that the autonomous vehicle is in a safe state, when the vehicle status information indicates that the components of the autonomous vehicle are fault-free and the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle meets the software update condition.
[0191] In an example where the corresponding software update condition includes that the autonomous vehicle is in a parked state and a safe state, when the vehicle status information indicates that the vehicle speed of the autonomous vehicle is zero and / or the autonomous vehicle is in park gear, and the components of the autonomous vehicle are fault-free and the autonomous vehicle is in a safe area, it is determined that the autonomous vehicle meets the software update condition.
[0192] Step S4500, when the retest result indicates that the autonomous vehicle meets the software update condition, update the software used by the autonomous vehicle from the second software to the first software.
[0193] In this embodiment, when the retest result indicates that the autonomous vehicle meets the software update condition, the software used by the autonomous vehicle is updated from the second software to the first software.
[0194] In one example, the version of the first software is lower than the version of the second software. When the autonomous vehicle stores the configuration file of the first software, the software used by the autonomous vehicle is updated from the second software to the first software. When the autonomous vehicle does not store the configuration file of the first software, the autonomous vehicle receives the configuration file of the first software sent by the server, and then based on the configuration file of the first software, updates the software used by the autonomous vehicle to the first software.
[0195] In another example, the version of the first software is higher than the version of the second software, and the autonomous vehicle does not store the configuration file of the first software. At this time, the autonomous vehicle receives the configuration file of the first software sent by the server 1100, and updates the software used based on the configuration file of the first software to the first software.
[0196] In one embodiment, after retesting whether the autonomous vehicle meets the software update condition according to the software update instruction in step S4400, the method further includes: step S4600.
[0197] Step S4600, when the retest result indicates that the autonomous vehicle does not meet the software update condition, return a second feedback message to the server.
[0198] In this embodiment, the second feedback message may be a message indicating that the retest result of the autonomous vehicle fails. When the server receives the second feedback message, it re-determines whether the autonomous vehicle meets the software update condition.
[0199] In one example, the second feedback information may carry the test items that failed the retest, so that the server can re-determine whether the failed test items meet the software update conditions. For example, if the autonomous driving vehicle is not in a safe area during the retest, the second feedback information carries information that the autonomous driving vehicle is not in a safe area, so that the server can re-detect whether the autonomous driving vehicle is in a safe area based on the second feedback information.
[0200] When the server determines that the autonomous driving vehicle meets the software update conditions, the server sends a software update instruction to the autonomous driving vehicle to trigger the autonomous driving vehicle to retest whether it meets the software update conditions. After retesting, if it is determined that it meets the software update conditions, the software used by the autonomous driving vehicle is updated from the second software to the first software.
[0201] According to the above steps S4100 to S4500, it can be known that according to the software update method of the embodiment of the present application, in the case of a high-risk event during the driving of the autonomous driving vehicle, the first feedback information about the high-risk event is sent to the server, thereby triggering the server to create multiple software update tasks, which can realize the targeted optimization of the autonomous driving vehicle software according to the feedback of the autonomous driving vehicle during use, and improve the practicality of the autonomous driving vehicle software. By sending the vehicle status information of the autonomous driving vehicle to the server according to the information acquisition request sent by the server, so that the server can determine whether the autonomous driving vehicle meets the set software update conditions according to the vehicle status information, and when the autonomous driving vehicle meets the software update conditions, the autonomous driving vehicle retests whether it meets the software update conditions. When the autonomous driving vehicle meets the software update conditions, the software used by the autonomous driving vehicle can be updated from the second software to the first software, which can realize the retest of whether the autonomous driving vehicle meets the software update conditions before the autonomous driving vehicle software is updated, and further improve the safety of the autonomous driving vehicle software update process.
[0202] <Method Example 3>
[0203] Figure 5 FIG. 1 is a schematic diagram of an interactive flow of a method for executing a software update in an autonomous driving system according to an embodiment of the present disclosure. The method may be Figure 1 The automated driving system 1000 shown is executed.
[0204] like Figure 5 As shown, the method includes:
[0205] Step S5210: When a high-risk event occurs during the driving of the autonomous driving vehicle, first feedback information is sent to the server 1100.
[0206] In this embodiment, the high-risk event may be an event with a relatively high potential for traffic accidents. For example, brake failure, steering system failure, etc. The first feedback information carries the specific information of the high-risk event. For example, the specific type and occurrence frequency of the high-risk event, etc.
[0207] In some other examples, the first feedback information may also be sent from the client 1300 to the server 1100.
[0208] Step S5110, when the server 1100 receives the first feedback information, it detects whether the software used by the autonomous vehicle is faulty.
[0209] Step S5120, when the server 1100 determines that the software used by the autonomous vehicle is faulty, it creates multiple software update tasks and enters the software update state.
[0210] In this embodiment, when the server 1100 determines that the high-risk event is caused by a software defect of the autonomous vehicle, it may create multiple software update tasks for all autonomous vehicles using the same software as that of the autonomous vehicle, and the multiple software update tasks correspond to the multiple autonomous vehicles one by one.
[0211] In another example, when the server 1100 determines that the high-risk event is caused by a software defect of the autonomous vehicle, it may create a software update task for the autonomous vehicle where the high-risk event occurs.
[0212] The software update task is a task of updating the software used by the autonomous vehicle from the second software to the first software. The second software may be the software related to the high-risk event. For example, when the autonomous vehicle has a brake failure, the corresponding second software is the brake software. The second software may also be all the software for autonomous driving including the software related to the high-risk event, and this is not limited here.
[0213] The software update state may be, for example, a state where the server 1100 cannot normally provide support for the autonomous driving of the autonomous vehicle.
[0214] Step S5130, the server 1100 creates a corresponding number of state machines according to the number of software update tasks and starts the multiple software update tasks in parallel.
[0215] In this embodiment, according to the software update tasks, state machines corresponding to each software update task may be created in multiple threads, and the multiple software update tasks may be started in parallel.
[0216] Step S5140, the server 1100 sends an information acquisition request according to the autonomous vehicle corresponding to the software update task.
[0217] Step S5220: The autonomous driving vehicle 1200 sends vehicle status information based on the information acquisition request.
[0218] Step S5150: The server 1100 determines whether the autonomous driving vehicle is in a parking state based on the vehicle status information.
[0219] In this embodiment, the server 1100 can determine that the autonomous driving vehicle is in a parking state when the vehicle status information indicates that the speed of the autonomous driving vehicle is zero and / or the autonomous driving vehicle is in a parking gear.
[0220] Step S5160: When the server 1100 determines that the autonomous driving vehicle is in a parking state, it determines whether the autonomous driving vehicle is in a safe state.
[0221] In this embodiment, when the server 1100 determines that the autonomous driving vehicle is in a parking state, if there is no fault in the components of the autonomous driving vehicle and / or the autonomous driving vehicle is in a safe area, the server 1100 determines that the autonomous driving vehicle is in a safe state.
[0222] In one example, components of an autonomous vehicle include at least one of an action component, a control component, a communication component, and a signal acquisition component.
[0223] In one example, the safety area includes at least one of a parking lot and a designated parking area for setting up an autonomous vehicle.
[0224] Step S5170: When the server 1100 determines that the autonomous driving vehicle is in a safe state, it sends a software update instruction.
[0225] In step S5230, the autonomous driving vehicle 1200 responds to the software update instruction and retests whether it is in a parking state and a safe state.
[0226] In this embodiment, when the vehicle status information indicates that the speed of the autonomous driving vehicle is zero and / or the autonomous driving vehicle is in a parking gear, it is determined that the autonomous driving vehicle is in a parking state. When the vehicle status information indicates that the components of the autonomous driving vehicle are not faulty and the autonomous driving vehicle is in a safe area, it is determined that the autonomous driving vehicle is in a safe state.
[0227] Step S5240, when the retest result indicates that the autonomous driving vehicle is in a safe state and a parked state, the software used is updated from the second software to the first software.
[0228] In some other examples, when the retest result indicates that the autonomous vehicle does not meet the software update conditions, the autonomous vehicle sends a second feedback message to the server, and based on the second feedback message, the server re-determines whether the autonomous vehicle is in a safe state and a parked state.
[0229] In some examples, after creating a corresponding number of state machines to start multiple software update tasks in step S5130, the server 1100 can display the progress of the multiple software update tasks.
[0230] In this embodiment, the progress of the multiple software update tasks can be displayed through the human-computer interaction interface configured by the server 1100.
[0231] In step S5180, when the multiple software update tasks end, the server 1100 resumes the operating state.
[0232] The above method embodiments focus on describing the differences from other embodiments. For the same or similar steps among the embodiments, reference can be made to each other.
[0233] <Apparatus Embodiment I>
[0234] Figure 6 The structural schematic diagram of a server according to an embodiment of the present disclosure is shown. As Figure 6 shown, the server 6000 includes: a creation module 6100, an acquisition module 6200, a determination module 6300, and an update module 6400.
[0235] Among them, the creation module 6100 is used to create multiple software update tasks, where the multiple software update tasks correspond to multiple autonomous vehicles one by one, and the software update task is a task of updating the software used by the autonomous vehicle to a first software.
[0236] The acquisition module 6200 is used to obtain the vehicle state information of the autonomous vehicle according to the software update task for the autonomous vehicle.
[0237] The determination module 6300 is used to determine whether the autonomous vehicle meets the set software update conditions according to the vehicle state information; where the software update conditions include that the autonomous vehicle is in a safe state.
[0238] The update module 6400 is used to batch update the software used by the autonomous vehicle from a second software to the first software when the autonomous vehicle meets the software update conditions; where the first software and the second software are software of different versions.
[0239] In one embodiment, the determination module 6300 is used to determine that the autonomous driving vehicle is in a safe state when the vehicle status information indicates that there is no fault in the components of the autonomous driving vehicle and the autonomous driving vehicle is in a safe area.
[0240] In one embodiment, the components of the autonomous driving vehicle include at least one of an action component, a control component, a communication component, and a signal acquisition component.
[0241] In one embodiment, the safety area includes at least one of a parking lot for setting up an autonomous driving vehicle and a designated parking area.
[0242] In one embodiment, the determination module 6300 is used to notify the operating personnel to perform safety processing on the autonomous driving vehicle when the autonomous driving vehicle does not meet the software update conditions; wherein the safety processing includes at least one of remotely controlling the autonomous driving vehicle to be in a safe area and repairing the components of the autonomous driving vehicle.
[0243] In one embodiment, the update module 6400 is used to send a software update instruction to the autonomous driving vehicle when the autonomous driving vehicle meets the software update conditions; wherein the software update instruction is used to trigger the autonomous driving vehicle to retest whether it meets the software update conditions; when the retest result indicates that the autonomous driving vehicle meets the software update conditions, the software used by the autonomous driving vehicle is updated from the second software to the first software.
[0244] In one embodiment, the determination module 6300 is used to redetermine whether the autonomous driving vehicle meets the software update condition when the re-test result indicates that the autonomous driving vehicle does not meet the software update condition; and send the software update instruction to the autonomous driving vehicle again when it is redetermined that the autonomous driving vehicle meets the software update condition.
[0245] In one embodiment, the update module 6400 is used to update the software used by the autonomous driving vehicle from the second software to the first software through an over-the-air download system.
[0246] In one embodiment, the creation module 6100 is used to create a corresponding number of state machines according to the number of the multiple software update tasks and start the multiple software update tasks in parallel;
[0247] The acquisition module 6200 is used to acquire the vehicle status information of the autonomous driving vehicle according to the software update tasks for the autonomous driving vehicle after starting the multiple software update tasks.
[0248] <Device Example 2>
[0249] Figure 7 shows a schematic structural diagram of an autonomous vehicle according to an embodiment of the present disclosure. As Figure 7 shown, the autonomous vehicle 7000 includes: a feedback module 7100, a sending module 7200, a rechecking module 7300, and an updating module 7400.
[0250] The feedback module 7100 is configured to send first feedback information about the high-risk event to the server when a high-risk event occurs during the driving of the autonomous vehicle; wherein, the first feedback information triggers the server to create a plurality of software update tasks, and the plurality of software update tasks are tasks for updating the software used by the autonomous vehicle to the first software.
[0251] The sending module 7200 is configured to send the vehicle status information of the autonomous vehicle to the server according to the information acquisition request sent by the server, so that the server determines whether the autonomous vehicle meets the set software update conditions according to the vehicle status information; wherein, the software update conditions include that the autonomous vehicle is in a parked state and a safe state.
[0252] The rechecking module 7300 is configured to receive the software update instruction sent by the server and recheck whether the autonomous vehicle meets the software update conditions according to the software update instruction.
[0253] The updating module 7400 is configured to update the software used by the autonomous vehicle from the second software to the first software when the recheck result indicates that the autonomous vehicle meets the software update conditions, wherein the second software and the first software are software of different versions.
[0254] <Device Embodiment>
[0255] This embodiment provides an electronic device, as Figure 8 shown, the electronic device 8000 includes a processor 8100 and a memory 8200.
[0256] In one embodiment, the electronic device is a server, the memory 8200 is configured to store a computer program, and the processor 8100 is configured to execute the autonomous vehicle software update method according to any method embodiment 1 under the control of the computer program.
[0257] In this embodiment, the server is, for example, the server 1100 as shown in Figure 1 and the like, which is not limited herein.
[0258] In another embodiment, the electronic device is an autonomous vehicle, and the memory 8200 is used to store a computer program. The processor 8100 is used to execute the method steps performed by the autonomous vehicle according to any method embodiment under the control of the computer program.
[0259] In this embodiment, the autonomous vehicle is, for example, the autonomous vehicle 1200 as shown in Figure 1 and the like, which is not limited herein.
[0260] The present invention may be a system, a method, and / or a computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for causing a processor to implement various aspects of the present invention.
[0261] The computer-readable storage medium may be a tangible device that can retain and store instructions for use by an instruction execution device. The computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device such as a punched card or raised structures in a groove having instructions stored thereon, and any suitable combination of the foregoing. The computer-readable storage medium as used herein is not construed as being a transitory signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0262] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to various computing / processing devices, or may be downloaded to an external computer or an external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include a copper transmission cable, an optical fiber transmission, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. The network adapter or network interface in each computing / processing device obtains the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.
[0263] The computer program instructions for carrying out the operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine - related instructions, microcode, firmware instructions, state - setting data, or source code or object code written in any combination of one or more programming languages, including object - oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer - readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand - alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or alternatively, may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer - readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field - programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer - readable program instructions to implement various aspects of the present invention.
[0264] Aspects of the present invention are described herein with reference to the flowchart and / or block diagram of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart and / or block diagram, and combinations of blocks in the flowchart and / or block diagram, can be implemented by computer - readable program instructions.
[0265] These computer - readable program instructions can be provided to a processor of a general - purpose computer, a special - purpose computer, or other programmable data - processing apparatus to produce a machine such that the instructions, when executed by the processor of the computer or other programmable data - processing apparatus, result in an apparatus that implements the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer - readable program instructions can also be stored in a computer - readable storage medium, which causes a computer, a programmable data - processing apparatus, and / or other devices to operate in a particular manner. Thus, the computer - readable medium storing the instructions includes a manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0266] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to generate a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other devices implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0267] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or by a combination of dedicated hardware and computer instructions. As is well known to those of ordinary skill in the art, implementations by hardware, by software, and by the combination of software and hardware are equivalent.
[0268] The embodiments of the present invention have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of the terms used herein is intended to best explain the principles of the embodiments, the practical application, or the improvement of technologies in the market, or to enable other ordinary skill in the art to understand the embodiments disclosed herein. The scope of the present invention is defined by the appended claims.
Claims
1. A software update method for an autonomous driving vehicle, include: Creating a plurality of software update tasks, wherein the plurality of software update tasks correspond one-to-one to a plurality of autonomous driving vehicles, and the software update tasks are tasks for updating software used by the autonomous driving vehicles to first software; According to a software update task for the autonomous driving vehicle, obtaining vehicle state information of the autonomous driving vehicle; Determining whether the autonomous driving vehicle meets a set software update condition according to the vehicle status information; wherein the software update condition includes that the autonomous driving vehicle is in a safe state; When the autonomous driving vehicle meets the software update condition, the software used by the autonomous driving vehicle is updated in batches from the second software to the first software; wherein the first software and the second software are different versions of software.
2. The method according to claim 1, It is characterized in that The determining, based on the vehicle status information, whether the autonomous driving vehicle is in a safe state includes: When the vehicle status information indicates that there are no faults in the components of the autonomous driving vehicle and the autonomous driving vehicle is in a safe area, it is determined that the autonomous driving vehicle is in a safe state.
3. The method according to claim 2, It is characterized in that The components of the autonomous driving vehicle include: at least one of an action component, a control component, a communication component and a signal acquisition component.
4. The method according to claim 2, It is characterized in that The safety area includes at least one of a parking lot for setting an autonomous driving vehicle and a designated parking area.
5. The method according to claim 1, It is characterized in that After determining whether the autonomous driving vehicle meets the set software update conditions according to the vehicle status information, the method further includes: In the event that the autonomous driving vehicle does not meet the software update conditions, the operating personnel are notified to perform safety processing on the autonomous driving vehicle; wherein the safety processing includes at least one of remotely controlling the autonomous driving vehicle to be in a safe area and repairing the components of the autonomous driving vehicle.
6. The method according to claim 1, It is characterized in that When the autonomous driving vehicle meets the software update condition, updating the software used by the autonomous driving vehicle from the second software to the first software in batches includes: When the autonomous driving vehicle meets the software update condition, sending a software update instruction to the autonomous driving vehicle; wherein the software update instruction is used to trigger the autonomous driving vehicle to retest whether it meets the software update condition; When the retest result indicates that the autonomous driving vehicle meets the software update condition, the software used by the autonomous driving vehicles is updated in batches from the second software to the first software.
7. The method according to claim 6, It is characterized in that After sending the software update instruction to the autonomous driving vehicle, the method further includes: If the retest result indicates that the autonomous driving vehicle does not meet the software update condition, re-determine whether the autonomous driving vehicle meets the software update condition; When it is re-determined that the autonomous driving vehicle meets the software update conditions, the software update instruction is sent to the autonomous driving vehicle again.
8. The method according to claim 1, It is characterized in that After creating the plurality of software update tasks, the method further includes: According to the number of the plurality of software update tasks, creating a corresponding number of state machines to start the plurality of software update tasks in parallel; After starting the multiple software update tasks, vehicle status information of the autonomous driving vehicle is obtained according to the software update tasks for the autonomous driving vehicle.
9. A server, include: A creation module, configured to create a plurality of software update tasks, wherein the plurality of software update tasks correspond one-to-one to a plurality of autonomous driving vehicles, and the software update tasks are tasks for updating software used by the autonomous driving vehicles to first software; An acquisition module, configured to acquire vehicle status information of the autonomous driving vehicle according to a software update task for the autonomous driving vehicle; A determination module, configured to determine whether the autonomous driving vehicle meets a set software update condition based on the vehicle status information; wherein the software update condition includes that the autonomous driving vehicle is in a safe state; An update module is used to batch update the software used by the autonomous driving vehicles from the second software to the first software when the autonomous driving vehicles meet the software update conditions; wherein the first software and the second software are different versions of software.
10. An autonomous driving vehicle, It is characterized in that It includes a memory and a processor, the memory is used to store a computer program, and the processor is used to execute the steps performed by the autonomous driving vehicle in the method according to any one of claims 1 to 8 under the control of the computer program.