Vehicle control method and device considering expected function safety, equipment and medium
By combining driver monitoring and steering wheel hands-off detection systems, the operation of the autonomous driving system switch is monitored and responded to in real time, which solves the problems of increased complexity and cost in improving the safety of the autonomous driving system switch, ensures that the driver is ready to operate, and improves safety and user experience.
Patent Information
- Application Number
- CN202511306405.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2025-11-14
AI Technical Summary
Existing technologies for improving the safety of automatic driving system switches suffer from increased complexity, higher costs, and a poorer user experience. In particular, they may lead to dangerous maneuvering when the driver has not adjusted the control status to a takeover ready state.
By combining the driver monitoring system and the steering wheel hands-off detection system, the system monitors the driver's operation of the automatic driving system switch in real time. When a shutdown operation is detected, the system responds based on the system fault status to ensure that the driver's control state is ready to take over, thereby reducing the ASIL level of the automatic driving system switch.
This approach reduces the safety risks associated with switching on and off the autonomous driving system without raising the ASIL level of existing components, ensuring safe vehicle operation, reducing system complexity and cost, and improving user experience.
Smart Images

Figure CN120942368A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle control technology, and in particular to a vehicle control method, apparatus, device, and medium that takes into account the expected functional safety. Background Technology
[0002] Current autonomous driving technologies are typically categorized into six levels, from 0 to 5. Higher-level automation systems, such as Level 3 and above, can autonomously perform core driving operations (e.g., acceleration, deceleration, steering) within specific scenarios or limited areas without continuous human intervention. When the driver needs to take over control, they can adjust the control state to a ready-to-take over and then deactivate the autonomous driving system by switching it off. Because the autonomous driving system switch is directly linked to the critical safety node of "activation / deactivation" of the autonomous driving function, triggering factors such as misuse of the switch could lead to dangerous situations where the system disengages before the driver has adjusted the control state to a ready-to-take over. Existing technologies typically aim to prevent dangerous actions by increasing the Automotive Safety Integrity Level (ASIL) of the autonomous driving system switch. However, methods for increasing the ASIL of the autonomous driving system switch present challenges such as increased complexity, higher costs, and a poorer user experience. Summary of the Invention
[0003] This invention provides a vehicle control method, apparatus, device, and medium that takes into account expected functional safety, and can reduce the ASIL level of the automatic driving system switch while ensuring that the driver's control state is in a takeover ready state when taking over vehicle control and without increasing the ASIL level of components widely used in the current industry.
[0004] In a first aspect, embodiments of the present invention provide a vehicle control method that takes into account expected functional safety, comprising:
[0005] During the activation of the autonomous driving system, real-time monitoring is performed to determine whether the driver performs a shutdown operation on the autonomous driving system switch; and
[0006] When a shutdown operation is detected, the shutdown operation is responded to based on whether the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are in a fault state.
[0007] Secondly, embodiments of the present invention provide a vehicle control device that takes into account expected functional safety, comprising:
[0008] The real-time monitoring module is used to monitor in real time whether the driver performs a shutdown operation on the autonomous driving system during its activation; and
[0009] The response module is used to respond to the closing operation based on whether the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are in a fault state when a closing operation is detected.
[0010] Thirdly, embodiments of the present invention also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement a vehicle control method considering intended functional safety as described in any of the embodiments of the present invention.
[0011] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the vehicle control method considering intended functional safety as described in any of the embodiments of the present invention.
[0012] This invention provides a vehicle control method, apparatus, device, and medium that considers expected functional safety. It combines a driver monitoring system and a steering wheel hands-off detection system as complementary and backup functions. After detecting a shutdown operation performed on the autonomous driving system switch, it accurately detects the driver's control state. Since the fault status of the driver monitoring system and steering wheel hands-off detection system determines whether the driver's control state can be determined through these systems, and the fault status of the autonomous driving system switch determines the reliability of the shutdown operation, this invention can respond promptly and accurately to shutdown operations based on the fault status of the driver monitoring system, steering wheel hands-off detection system, and autonomous driving system switch. Furthermore, it can reduce the ASIL level of the autonomous driving system switch without increasing the ASIL level of widely used components in the industry, ensuring the driver's control state is ready for takeover when taking over vehicle control. This avoids expected functional safety-related risks caused by driver misuse of the switch, failure to takeover readiness, etc., ensuring safe vehicle operation, reducing vehicle system complexity, reducing vehicle system costs, and improving user experience. Attached Figure Description
[0013] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a schematic flowchart of a vehicle control method considering expected functional safety provided in an embodiment of the present invention;
[0015] Figure 2 This is another schematic flowchart of the vehicle control method considering expected functional safety provided in the embodiments of the present invention;
[0016] Figure 3 This is another schematic flowchart of the vehicle control method considering expected functional safety provided in the embodiments of the present invention;
[0017] Figure 4 This is another schematic flowchart of the vehicle control method considering expected functional safety provided in the embodiments of the present invention;
[0018] Figure 5 This is a schematic diagram of a vehicle control device considering the intended functional safety provided in an embodiment of the present invention;
[0019] Figure 6 This is a schematic diagram of an electronic identification structure provided in an embodiment of the present invention. Detailed Implementation
[0020] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0021] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0022] Figure 1This is a flowchart illustrating a vehicle control method considering expected functional safety provided in an embodiment of the present invention. This embodiment is applicable to vehicle control scenarios with an automation level of 3 or higher. The method can be executed by a vehicle control device considering expected functional safety provided in this embodiment, which can be implemented in software and / or hardware. In one specific embodiment, the device can be integrated into an electronic device, such as a computer or server. The following embodiments will illustrate this using the integration of the device into an electronic device as an example. (Reference) Figure 1 The method may specifically include the following steps:
[0023] Step 101: During the activation of the autonomous driving system, real-time monitoring is performed to determine whether the driver performs a shutdown operation on the autonomous driving system switch. This step facilitates timely and accurate response to shutdown operations based on the driver monitoring system, steering wheel hands-off detection system, and whether the autonomous driving system switch is in a faulty state.
[0024] Specifically, the aforementioned autonomous driving system may include autonomous driving systems for vehicles with an ASIL level greater than 3.
[0025] Specifically, the aforementioned autonomous driving system switch can be any type of switch, such as a physical button switch, a touch screen soft switch, or a voice control switch.
[0026] Specifically, the driver's actions to turn off the autonomous driving system can be monitored in real time by detecting whether a circuit signal corresponding to the shutdown operation is present.
[0027] Optionally, during the activation of the autonomous driving system, real-time fault diagnosis can be continuously performed on the driver monitoring system, the steering wheel hands-off detection system, and the autonomous driving system switch.
[0028] Step 102: Upon detecting a shutdown operation, respond to the shutdown operation based on whether the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are in a fault state. Building upon step 101, this step enables a timely and accurate response to shutdown operations. Furthermore, it lowers the ASIL level of the automatic driving system switch without requiring an increase in the ASIL level of widely used components, ensuring the driver's control state is ready for takeover when resuming vehicle operation. This avoids anticipated functional safety risks caused by driver misuse of the switch, incomplete takeover readiness, or other triggering factors, thereby ensuring safe vehicle operation, reducing vehicle system complexity, lowering system costs, and improving user experience.
[0029] Optionally, the process of responding to and turning off the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch based on whether they are in a fault state includes: issuing corresponding system fault prompts and / or issuing corresponding operation state adjustment prompts.
[0030] In a specific example, when the driver monitoring system malfunctions, a voice prompt indicating the malfunction is issued, along with a prompt to adjust the driver's gaze to focus on the road ahead, so that the driver can adjust the gaze that the driver monitoring system cannot detect to a ready-to-take-over state.
[0031] The following further describes the vehicle control method considering expected functional safety provided by embodiments of the present invention, such as... Figure 2 As shown, that is Figure 1 Step 102 may include the following steps:
[0032] Step 102A1: If the driver monitoring system, steering wheel hands-off detection system, or automatic driving system switch is in a fault state, determine the takeover confirmation operation based on the system type corresponding to the fault state.
[0033] Optionally, the process of determining the takeover confirmation operation based on the system type corresponding to the fault state includes: when the driving system switch is in a fault state, determining the takeover confirmation operation as executing a forced takeover operation.
[0034] Specifically, the aforementioned forced takeover operation can be the operation of turning the steering wheel, pressing the accelerator pedal, and / or pressing the brake pedal.
[0035] Step 102A2: Issue a prompt to adjust the control status and perform a takeover confirmation operation, so that the driver adjusts the control status to the takeover ready state and confirms that the shutdown operation is not a misuse operation.
[0036] Specifically, the aforementioned prompts for adjusting the control status could be, for example, prompting the driver to hold the steering wheel and look straight ahead.
[0037] Specifically, the prompts for performing the takeover confirmation operation may be to prompt the driver to exit the automatic driving system by turning the steering wheel, pressing the accelerator pedal, and / or pressing the brake pedal.
[0038] Step 102A3: Within the first predetermined time period after issuing the prompt to adjust the control status and perform the takeover confirmation operation, monitor whether the driver has performed the takeover confirmation operation.
[0039] Specifically, the driver's takeover confirmation can be monitored by one or two of the following three systems: the driver monitoring system, the steering wheel hands-off detection system, and the automatic driving system, provided that no malfunction occurs. For example, when the driver monitoring system is functioning correctly, it can monitor specific hand gestures made by the driver, such as making an "OK" gesture.
[0040] Step 102A4: If no takeover confirmation operation is detected within the first specified time period, the least risk action is performed through the automatic driving system.
[0041] Specifically, the least risky action mentioned above could be to slowly decelerate and safely pull over to the side of the road, or to smoothly decelerate to a stop within the current lane.
[0042] Optionally, if a takeover confirmation operation is detected within the first specified time period, the automatic driving system is shut down.
[0043] Optionally, the vehicle control method considering expected functional safety provided in the embodiments of the present invention further includes: if a forced takeover operation is detected within a first predetermined time period after issuing a prompt to adjust the control state and perform a takeover confirmation operation, the automatic driving system is turned off.
[0044] This invention can minimize the risk of dangerous vehicle operation when the driver monitoring system, steering wheel hands-off detection system, or automatic driving system switch is malfunctioning and the driver's operating state cannot be accurately determined to be in a takeover ready state. It prompts the driver to perform a takeover confirmation operation and provides a specified execution time for the operation. If no takeover confirmation operation is detected within the specified time, it performs a minimum-risk action. This is beneficial in situations where the driver unintentionally does not operate the automatic driving system switch and cannot promptly adjust the control state to a takeover ready state, such as when the driver is asleep and accidentally touches the switch.
[0045] The vehicle control method considering the expected functional safety provided by the embodiments of the present invention is further described below.
[0046] Optional, Figure 2 Step 102A1 includes: when the driving system switch is not in a fault state and either the driver monitoring system or the steering wheel hands-off detection system is in a fault state, determining the takeover confirmation operation as performing a re-shutdown operation on the automatic driving system switch.
[0047] Optional, such as Figure 3 As shown, the vehicle control method considering expected functional safety provided in this embodiment of the invention includes the following steps:
[0048] Step 301: During the activation of the autonomous driving system, monitor in real time whether the driver performs a shutdown operation on the autonomous driving system switch.
[0049] Step 302: When a shutdown operation is detected, if the driving system switch is not in a fault state but either the driver monitoring system or the steering wheel hands-off detection system is in a fault state, a prompt is issued to adjust the control state and perform a shutdown operation on the automatic driving system switch again.
[0050] Step 303: The system detects whether the driver's control status is in a takeover ready state by checking the non-faulty state of the two systems.
[0051] Optionally, the process described above for detecting whether the driver's control state is in a takeover ready state through the non-faulty states of the two systems includes:
[0052] When the driver monitoring system is in a fault state and the steering wheel hands-off detection system is in a normal state, the driver's steering wheel grip state is detected by the steering wheel hands-off detection system. When the driver's steering wheel grip state is in an effective grip state, the driver's control state is determined to be ready to take over.
[0053] Specifically, an effective grip state for the aforementioned steering wheel grip state can be, for example, a state in which the driver's hands are in contact with the steering wheel and the contact force is greater than a force threshold, and the contact area is greater than an area threshold.
[0054] Optionally, the process described above for detecting whether the driver's control state is in a takeover ready state through the non-faulty states of the two systems includes:
[0055] When the driver monitoring system is in a non-faulty state and the steering wheel hands-off detection system is in a faulty state, the driver's gaze state is detected and obtained through the driver monitoring system. When the driver's gaze state is in a driving-focused state, the driver's control state is determined to be in a takeover ready state.
[0056] Specifically, the above-mentioned driving focus state can be characterized by the eyes maintaining a normal degree of opening and closing, without frequent blinking, prolonged eye closure, or a blank stare, and with the gaze mostly focused on the safe zone of the road ahead, without prolonged head turning, looking down, or looking up, which are significant deviations from the normal driving posture.
[0057] Step 304: If a shutdown operation is detected again within the first predetermined time period and the driver's control status is in the takeover ready state, the automatic driving system is shut down.
[0058] Step 305: If no further shutdown operation is detected within the first specified time period or the driver's control status is not in a takeover ready state, the least risk action is performed through the autonomous driving system.
[0059] Specifically, if a shutdown operation is detected again within the first predetermined time period, but the driver's control status is not in a takeover ready state, a prompt will be issued again to adjust the control status and perform a takeover confirmation operation. Within the first predetermined time period after issuing the prompt to adjust the control status, the system will monitor whether the driver performs a takeover confirmation operation, and after detecting the corresponding takeover confirmation operation, the system will be shut down.
[0060] In a specific instance, if the driving system switch is not in a fault state, but the driver monitoring system and the steering wheel hands-off detection system are both in a fault state, if a takeover confirmation operation is detected within the first specified time period, the automatic driving system will perform the least risky action, issue another prompt to adjust the control state, and deactivate the automatic driving system.
[0061] The embodiments of the present invention can utilize the driver monitoring system and the steering wheel hands-off detection system as a backup system to monitor whether the driver's control status is ready to take over when the other system fails. This can effectively avoid dangerous control phenomena caused by the inability to determine the driver's control status when the driver monitoring system or the steering wheel hands-off detection system fails.
[0062] The vehicle control method considering the expected functional safety provided by the embodiments of the present invention is further described below.
[0063] like Figure 4 As shown, that is Figure 1 Step 102 includes the following steps:
[0064] Step 102B1: If the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are not in a fault state, determine whether the driver's control state is in a takeover ready state through the driver monitoring system and steering wheel hands-off detection system.
[0065] Step 102B2: When the determination result is that the driver's operating status is not in the takeover ready state, a prompt to adjust the control status is issued so that the driver can adjust the control status to the takeover ready state.
[0066] Optionally, the automatic driving system can be deactivated when the driver's control state is determined to be ready to take over.
[0067] Specifically, a takeover request can be issued before the autonomous driving system is turned off.
[0068] Optionally, if the determination result is that the driver's operating status is not in a takeover ready state, a prompt to adjust the control status is issued so that the driver adjusts the control status to a takeover ready state.
[0069] Step 102B3: The driver's control status is re-determined as ready to take over by the driver monitoring system and the steering wheel hands-off detection system.
[0070] Step 102B4: When the result of the determination is that the driver's operation status is ready to take over, a prompt is issued to perform a shutdown operation on the automatic driving system switch again.
[0071] Step 102B5: Within a second predetermined time period after issuing a prompt to perform a re-shutdown operation on the automatic driving system switch, monitor whether the driver performs the re-shutdown operation.
[0072] Step 102B6: If a second shutdown operation is detected within a second predetermined time period after a prompt to perform a shutdown operation on the automatic driving system switch is issued, the automatic driving system is shut down.
[0073] Specifically, if no further shutdown operation is detected within the second specified time period after the prompt to perform a shutdown operation on the automatic driving system switch is issued, the system will start executing step 101.
[0074] Optionally, step 102B1 or step 102B3 includes the following steps: when the driver's steering wheel grip is in an effective grip state and the driver's gaze is in a driving-focused state, the driver's control state is determined to be in a takeover-ready state; when the driver's steering wheel grip is not in an effective grip state, or the driver's gaze is not in a driving-focused state, the driver's control state is determined to be in a takeover-ready state.
[0075] Optionally, when the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are not in a fault state, a prompt can be issued to select and execute one of three actions as a takeover confirmation operation: the driver monitoring system can recognize a specific hand movement, the steering wheel hands-off detection system can recognize a specific grip movement, and the automatic driving system switch can be turned off again.
[0076] This invention combines a driver monitoring system and a steering wheel hands-off detection system. The two systems complement each other's functional gaps and can accurately determine whether the driver's operating state is ready to take over. Therefore, it can more effectively ensure that the driver's operating state is ready to take over when taking over vehicle control.
[0077] Figure 5 This is a structural diagram of a vehicle control device considering expected functional safety provided in an embodiment of the present invention. This device is suitable for executing the vehicle control method considering expected functional safety provided in an embodiment of the present invention. Figure 5 As shown, the device may specifically include:
[0078] The real-time monitoring module 501 is used to monitor in real time whether the driver performs a shutdown operation on the autonomous driving system switch during the activation of the autonomous driving system. This module can respond promptly and accurately to the shutdown operation of the autonomous driving system based on the driver monitoring system, the steering wheel hands-off detection system, and whether the autonomous driving system switch is in a fault state.
[0079] The response module 502 is used to respond to a shutdown operation upon detection, based on whether the driver monitoring system, steering wheel hands-off detection system, and autonomous driving system switch are in a fault state. This module can provide a timely and accurate response to shutdown operations, and can lower the ASIL level of the autonomous driving system switch without increasing the ASIL level of widely used components in the industry, while ensuring that the driver's control state is in a takeover ready state when taking over vehicle control. This avoids anticipated functional safety-related risks caused by factors such as driver misuse of the switch or failure to take over the takeover state, thereby ensuring the safe operation of the vehicle, reducing the complexity of the vehicle system, reducing the cost of the vehicle system, and improving the user experience.
[0080] Optionally, the response module 502 can be specifically used to: determine a takeover confirmation operation based on the system type corresponding to the fault state if the driver monitoring system, steering wheel hands-off detection system, or automatic driving system switch is in a fault state; issue a prompt to adjust the control state and perform the takeover confirmation operation so that the driver adjusts the control state to the takeover ready state and confirms that the shutdown operation is not a misuse operation; monitor whether the driver performs the takeover confirmation operation within a first predetermined time period after issuing the prompt to adjust the control state and perform the takeover confirmation operation; and if no takeover confirmation operation is detected within the first predetermined time period, perform a minimum risk action through the automatic driving system.
[0081] Optionally, the response module 502 can be specifically used to determine the takeover confirmation operation as performing a re-shutdown operation on the automatic driving system switch when the driving system switch is not in a fault state and one of the two systems, the driver monitoring system and the steering wheel hands-off detection system, is in a fault state.
[0082] Optionally, the response module 502 can be specifically used to, within a first predetermined time period after issuing a prompt to adjust the control state and perform a takeover confirmation operation, detect whether the driver's control state is in a takeover ready state through the non-faulty state of the two systems; if a shutdown operation is detected again within the first predetermined time period and the driver's control state is in a takeover ready state, shut down the automatic driving system; if no shutdown operation is detected again within the first predetermined time period or the driver's control state is not in a takeover ready state, perform a minimum risk action through the automatic driving system.
[0083] Optionally, the response module 502 can be specifically used to determine the takeover confirmation operation as a forced takeover operation when the driving system switch is in a fault state.
[0084] Optionally, the response module 502 can be specifically used to shut down the automatic driving system if a forced takeover operation is detected within a first predetermined time period after issuing a prompt to adjust the control status and perform a takeover confirmation operation.
[0085] Optionally, the response module 502 can be specifically used to detect and obtain the driver's steering wheel grip state through the steering wheel grip detection system when the driver monitoring system is in a fault state and the steering wheel hand-off detection system is in a non-fault state, and determine the driver's control state as ready to take over when the driver's steering wheel grip state is an effective grip state.
[0086] When the driver monitoring system is in a non-faulty state and the steering wheel hands-off detection system is in a faulty state, the driver's gaze state is detected and obtained through the driver monitoring system. When the driver's gaze state is in a driving-focused state, the driver's control state is determined to be in a takeover ready state.
[0087] Optionally, the response module 502 can be specifically used to: if the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are not in a fault state, determine whether the driver's control state is in a takeover ready state through the driver monitoring system and steering wheel hands-off detection system; if the determination result is that the driver's control state is in a takeover ready state, deactivate the automatic driving system; if the determination result is that the driver's control state is not in a takeover ready state, issue a prompt to adjust the control state so that the driver adjusts the control state to a takeover ready state; determine again whether the driver's control state is in a takeover ready state through the driver monitoring system and steering wheel hands-off detection system; if the determination result is again that the driver's control state is in a takeover ready state, issue a prompt to perform a reactivation operation on the automatic driving system switch; monitor whether the driver performs the reactivation operation within a second predetermined time period after issuing the prompt to perform the reactivation operation on the automatic driving system switch; if a reactivation operation is detected within the second predetermined time period after issuing the prompt to perform the reactivation operation on the automatic driving system switch, deactivate the automatic driving system.
[0088] Optionally, the response module 502 can be specifically used to detect and obtain the driver's steering wheel grip state through the steering wheel hands-off detection system and the driver's gaze state through the driver monitoring system; and when the driver's steering wheel grip state is an effective grip state and the driver's gaze state is a driving-focused state, determine that the driver's control state is a takeover-ready state; and when the driver's steering wheel grip state is not an effective grip state or the driver's gaze state is not a driving-focused state, determine that the driver's control state is not a takeover-ready state.
[0089] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is merely an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the functional modules described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0090] This invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the vehicle control method considering intended functional safety provided in any of the above embodiments.
[0091] This invention also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the vehicle control method considering intended functional safety provided in any of the above embodiments.
[0092] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements a vehicle control method considering intended functional safety as described in any of the embodiments of this invention.
[0093] The following is for reference. Figure 6 It shows a schematic diagram of the structure of a computer system 600 suitable for implementing an electronic device according to embodiments of the present invention. Figure 6 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.
[0094] like Figure 6As shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 602 or programs loaded from storage section 608 into random access memory (RAM) 603. The RAM 603 also stores various programs and data required for the operation of the system 600. The CPU 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0095] The following components are connected to I / O interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to I / O interface 605 as needed. A removable medium 611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 610 as needed so that computer programs read from it can be installed into storage section 608 as needed.
[0096] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 609, and / or installed from removable medium 611. When the computer program is executed by central processing unit (CPU) 601, it performs the functions defined above in the system of this invention.
[0097] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0098] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0099] The modules and / or units described in the embodiments of the present invention can be implemented in software or hardware. The described modules and / or units can also be housed in a processor; for example, a processor can be described as including a real-time monitoring module and a response module. The names of these modules do not necessarily limit the module itself.
[0100] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to include: real-time monitoring of whether the driver performs a shutdown operation on the autonomous driving system switch during activation of the autonomous driving system; and, upon detecting a shutdown operation, responding to the shutdown operation based on whether the driver monitoring system, the steering wheel hands-off detection system, and the autonomous driving system switch are in a fault state.
[0101] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A vehicle control method considering intended functional safety, characterized in that, include: During the activation of the autonomous driving system, real-time monitoring is performed to determine whether the driver performs a shutdown operation on the autonomous driving system switch; as well as When a shutdown operation is detected, the system responds to the shutdown operation based on whether the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are in a fault state.
2. The vehicle control method considering expected functional safety according to claim 1, characterized in that, The method of responding to the shutdown operation based on whether the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are in a fault state includes: If the driver monitoring system, steering wheel hands-off detection system, or automatic driving system switch is in a fault state, the takeover confirmation operation is determined based on the system type corresponding to the fault state. A prompt is issued to adjust the control status and perform a takeover confirmation operation, so that the driver adjusts the control status to the takeover ready state and confirms that the shutdown operation is not a misuse operation; Within the first predetermined time period after issuing the prompt to adjust control status and perform takeover confirmation, the system monitors whether the driver performs the takeover confirmation operation; and If no takeover confirmation operation is detected within the first specified time period, the lowest-risk action will be performed through the autonomous driving system.
3. The vehicle control method considering expected functional safety according to claim 2, characterized in that, The takeover confirmation operation based on the system type corresponding to the fault state includes: When the driving system switch is not in a fault state but one of the two systems, the driver monitoring system and the steering wheel hands-off detection system, is in a fault state, the takeover confirmation operation will be determined as performing a re-shutdown operation on the automatic driving system switch. The method further includes: Within the first predetermined time period after issuing the prompt to adjust the control status and perform the takeover confirmation operation, the system in the non-faulty state of the two systems detects whether the driver's control status is in the takeover ready state. If a shutdown operation is detected again within the first specified time period and the driver's control status is ready to take over, the automatic driving system will be shut down. If no further shutdown operation is detected within the first specified time period, or if the driver's control status is not in a takeover ready state, the lowest risk action will be performed through the autonomous driving system.
4. The vehicle control method considering expected functional safety according to claim 2, characterized in that, The takeover confirmation operation based on the system type corresponding to the fault state includes: When the driving system switch is in a fault state, the takeover confirmation operation is determined to be a forced takeover operation; The method further includes: If a forced takeover operation is detected within the first predetermined time period after issuing a prompt to adjust the control status and perform a takeover confirmation operation, the autopilot system will be shut down.
5. The vehicle control method considering intended functional safety according to claim 3, characterized in that, The system detection of whether the driver's control state is in a takeover ready state through the non-fault state of the two systems includes: When the driver monitoring system is in a fault state and the steering wheel hands-off detection system is in a non-fault state, the driver's steering wheel grip state is detected and obtained through the steering wheel hands-off detection system. When the driver's steering wheel grip state is in an effective grip state, the driver's control state is determined to be in a takeover ready state. When the driver monitoring system is in a non-faulty state and the steering wheel hands-off detection system is in a faulty state, the driver's gaze state is detected and obtained through the driver monitoring system. When the driver's gaze state is in a state of focused driving, the driver's control state is determined to be in a state of ready to take over.
6. The vehicle control method considering intended functional safety according to claim 1, characterized in that, The method of responding to the shutdown operation based on whether the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are in a fault state includes: If the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are not in a fault state, the driver monitoring system and steering wheel hands-off detection system are used to determine whether the driver's control state is ready to take over. When the determination result indicates that the driver's control status is ready to take over, the automatic driving system is deactivated; When the determination result is that the driver's operating status is not ready to take over, a prompt to adjust the control status is issued so that the driver can adjust the control status to the ready to take over. The driver monitoring system and steering wheel hands-off detection system are used to determine again whether the driver's control status is ready to take over. If the driver's operating status is determined to be ready to take over again, a prompt will be issued to perform a shutdown operation on the automatic driving system switch; Within a second predetermined time period after issuing a prompt to turn the autonomous driving system off again, the system monitors whether the driver has performed the action to turn it off again. If a second shutdown operation is detected within the second specified time period after the prompt to perform a shutdown operation on the automatic driving system switch is issued, the automatic driving system is shut down.
7. The vehicle control method considering intended functional safety according to claim 6, characterized in that, The step of determining whether the driver's control state is ready to take over through the driver monitoring system and the steering wheel hands-off detection system, or the step of determining whether the driver's control state is ready to take over through the driver monitoring system and the steering wheel hands-off detection system again, includes: The driver's steering wheel grip status is detected by the steering wheel hands-off detection system, and the driver's line of sight status is detected by the driver monitoring system. When the driver's steering wheel grip is in an effective grip state and the driver's gaze is in a focused driving state, the driver's control state is determined to be in a ready-to-take-over state; when the driver's steering wheel grip is not in an effective grip state, or the driver's gaze is not in a focused driving state, the driver's control state is determined to be in a ready-to-take-over state.
8. A vehicle control device considering intended functional safety, characterized in that, include: The real-time monitoring module is used to monitor in real time whether the driver performs a shutdown operation on the autonomous driving system during the activation of the autonomous driving system. as well as The response module is used to respond to the closing operation based on whether the driver monitoring system, steering wheel hands-off detection system, and automatic driving system switch are in a fault state when a closing operation is detected.
9. A vehicle comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the vehicle control method that takes into account the intended functional safety as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the vehicle control method that takes into account the intended functional safety as described in any one of claims 1 to 7.