Adaptive Response Control Method and System for Longitudinal Control Redundancy System of Automated Vehicles in Heavy-Duty Trucks

CN121516017BActive Publication Date: 2026-09-01SINO TRUK JINAN POWER CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511946021.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-09-01
Estimated Expiration
2045-12-22

AI Technical Summary

Technical Problem

[0003]对于摄像头短暂污损、单一非关键传感器数据异常等轻微故障,现有刚性策略会直接触发不必要的路径切换甚至制动介入,既破坏了自动驾驶的连续性、降低运输效率,在重载工况下还可能因频繁非必要制动干预引入新的安全风险与车辆损耗

Benefits of technology

[0063] As can be seen from the above technical solutions, this application has the following advantages: it changes the rigid logic of traditional master-slave two-state switching, and can take the most appropriate countermeasures according to the actual impact of the fault, thereby maximizing the continuity of autonomous driving, operational efficiency and ride comfort while ensuring functional safety, and avoiding unnecessary degradation or emergency intervention caused by frequent non-critical faults.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121516017B_ABST
    Figure CN121516017B_ABST
Patent Text Reader

Abstract

This application relates to the field of vehicle control technology, specifically to an adaptive response control method and system for a longitudinal control redundancy system for autonomous driving of heavy-duty vehicles. The method includes: continuously monitoring the status of the main and backup control paths and each component of the system, and determining the fault level in real time, including normal, minor, moderate, and severe faults. A graded response strategy is executed according to the fault level: During normal operation, the main control is activated, and the backup system performs hot standby verification; during minor faults, the main control is activated and backup resource verification compensation is enabled; during moderate faults, the system quickly switches to the backup path and maintains braking force; during severe faults, the emergency path is immediately activated, deceleration is limited, and an alarm is triggered to ensure safe vehicle deceleration. All events are recorded and reported. This achieves a leap from rigid switching to intelligent graded adaptive control, improving system continuity and efficiency while ensuring safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle control technology, specifically to an adaptive response control method and system for a longitudinal control redundancy system for autonomous driving of heavy-duty vehicles. Background Technology

[0002] In the field of longitudinal control for autonomous driving of heavy-duty vehicles, redundancy is the core of ensuring driving safety. However, existing redundancy control schemes mostly adopt simple primary-backup two-state switching logic, switching to the backup path only when the primary path is detected to be in failure, lacking fine differentiation of the degree of failure and adaptive response capability.

[0003] For minor faults such as temporary camera smudges or abnormal data from a single non-critical sensor, existing rigid strategies can directly trigger unnecessary path switching or even braking intervention. This disrupts the continuity of autonomous driving, reduces transportation efficiency, and, under heavy-load conditions, may introduce new safety risks and vehicle wear due to frequent unnecessary braking interventions. Furthermore, this solution does not fully consider the special characteristics of complex scenarios such as heavy-duty vehicles and long downhill slopes, resulting in poor scenario adaptability of redundant control and an inability to meet safety requirements. Therefore, a dynamic adaptive response scheme based on fault levels is urgently needed to balance safety and operational efficiency. Summary of the Invention

[0004] To address the aforementioned problems, this invention provides an adaptive response control method and system for a longitudinal control redundancy system for autonomous driving of heavy-duty vehicles.

[0005] In a first aspect, the present invention provides an adaptive response control method for a longitudinal control redundancy system for autonomous driving of heavy-duty vehicles. The redundancy system includes at least a primary control path and a backup control path. The method implements a graded response based on a preset fault level, and includes the following steps:

[0006] S1. Continuously monitor the working status and performance parameters of the main control path, backup control path and their associated sensors, actuators and control units;

[0007] S2. Based on the monitored working status and performance parameters, determine the current fault level of the system in real time. The fault level includes normal working condition, minor fault, moderate fault and severe fault.

[0008] S3. Based on the real-time determined fault level, execute the control strategy corresponding to that fault level, wherein:

[0009] When the condition is determined to be normal, the main control path performs longitudinal control, while the backup control path synchronizes control commands and vehicle status data in a hot backup manner and performs periodic deviation checks.

[0010] When a minor fault is identified, control of the main control path is maintained, while sensor data or computing resources of the backup control path are used to perform real-time verification and compensation of the output of the main control path to ensure functional safety.

[0011] When a moderate fault is determined, within the preset first time threshold, the longitudinal control is switched from the main control path to the backup control path, and the braking force output is kept not lower than the preset first braking force holding threshold during the switching process.

[0012] When a serious fault is determined, an emergency fault tolerance mechanism is activated within a preset second time threshold. The emergency fault tolerance mechanism includes at least activating an emergency backup path, limiting the maximum deceleration of the vehicle, and triggering a vehicle warning. The second time threshold is less than the first time threshold to ensure that the vehicle enters a controllable deceleration state.

[0013] S4. Record fault events, triggered response actions, and vehicle status and control parameters related to the fault and response, and report them through the vehicle communication network.

[0014] Based on the fault level, a graded response is implemented. Under normal operating conditions, the main path control and backup path hot backup take into account both control efficiency and redundancy reliability. In the case of minor faults, the main path maintains control and the backup path compensates for data to avoid unnecessary switching. In the case of moderate faults, the system can quickly and seamlessly take over and ensure stable braking force. In the case of severe faults, the system can provide emergency response and strictly control deceleration. This solves the problems of poor scenario adaptability and single response strategy in existing solutions, balances the safety and operational continuity of autonomous driving for heavy vehicles, and meets the stringent requirements of complex scenarios such as heavy loads and long downhill slopes.

[0015] As a preferred embodiment of the technical solution of the present invention, the criteria for determining a minor fault include any of the following:

[0016] The confidence level of data from any sensor in the main control path is lower than the first normal operating threshold.

[0017] There is a continuous abnormal deviation between the monitoring data of the same physical quantity between the main control path and the backup control path, and the deviation does not exceed the allowable redundancy verification tolerance.

[0018] The main control unit's computing resource utilization exceeds the first load threshold affecting the execution of non-critical tasks.

[0019] It enables refined fault identification, providing accurate judgment criteria for minor fault response strategies such as data compensation rather than path switching, reducing unnecessary control interruptions, lowering safety risks and vehicle wear caused by frequent switching under heavy load conditions, and ensuring that functional safety is not degraded.

[0020] As a preferred embodiment of the technical solution of the present invention, the criteria for determining a moderate fault include any of the following:

[0021] The actuator response delay of the main control path exceeds the first permissible delay threshold to ensure the longitudinal stability of the vehicle;

[0022] The duration of the communication interruption between the main control unit and the vehicle chassis system responsible for longitudinal control exceeds the first permissible interruption threshold that affects the continuity of control.

[0023] The deviation between the braking force output by the main control path and the target value continues to exceed the first permissible deviation threshold that affects tracking accuracy;

[0024] The critical environmental awareness function of the main control path fails, and this function cannot be fully taken over by the awareness system of the backup control path while meeting the control accuracy requirements.

[0025] Accurately screen fault scenarios that require path switching, ensuring that the backup path takes over only when the primary path cannot maintain effective control, avoiding over-response for minor faults, preventing delays in handling moderate faults, and ensuring the rationality of the switching timing.

[0026] As a preferred embodiment of the technical solution of the present invention, the criteria for determining a serious fault include any of the following situations:

[0027] The status and command synchronization channel between the main control unit and the backup control unit has completely failed.

[0028] The braking output capabilities of both the primary control path and the backup control path simultaneously decrease to a level that cannot meet basic braking requirements.

[0029] The maximum safe deceleration of the vehicle, as assessed in real time based on the available resources of the current system, is lower than the minimum safe deceleration necessary to maintain the current driving state.

[0030] The standby status of the emergency backup path used for fault tolerance is unavailable.

[0031] It can quickly identify extreme risk scenarios, provide accurate triggering basis for emergency response mechanisms, and ensure that the highest level of safety response is immediately activated when the system faces the risk of collapse, so as to minimize the probability of serious accidents such as collisions and cargo overturning caused by serious malfunctions of heavy-duty and high-inertia heavy vehicles.

[0032] As a preferred embodiment of the technical solution of the present invention, in the response to a moderate fault, the backup control path is a braking circuit independent of the main control path, the first time threshold is set according to the vehicle dynamics stability requirements, and the first braking force threshold is a preset target value for braking force retention rate.

[0033] To ensure the stability and reliability of the switching process during moderate faults, an independent braking circuit is used to prevent the main path fault from interfering with the output of the backup path. The time threshold for dynamic adaptation ensures that the switching is fast and does not affect the vehicle's attitude. The target value for brake force retention rate ensures the accuracy of vehicle speed control during the switching process and avoids safety hazards caused by sudden changes in brake force due to switching in heavy-duty vehicles.

[0034] As a preferred embodiment of the technical solution of the present invention, in the response to a serious fault, the emergency fault tolerance mechanism is to switch to a mechanical emergency path, the second time threshold is set according to the urgency of avoiding collision, and the maximum safe deceleration is limited according to the vehicle load and road surface adhesion conditions.

[0035] It provides the most reliable safety backup plan for serious malfunctions. The mechanical emergency path is not affected by electronic system failures. The design, which is shorter than the first time threshold, ensures the timeliness of emergency response. Based on load and road conditions, it limits deceleration to effectively avoid secondary risks such as cargo overturning and tire lock-up caused by excessive deceleration of heavy vehicles. At the same time, it enhances the risk avoidance ability of surrounding traffic participants through warning functions.

[0036] As a preferred embodiment of the technical solution of the present invention, the step of real-time assessment of the maximum safe deceleration of the vehicle based on the currently available system resources is as follows:

[0037] The availability status and performance degradation coefficient of all braking actuators are acquired and maintained in real time. The braking actuators include at least a line-controlled braking unit for the main control path, an independent hydraulic braking unit for the backup control path, and a non-friction braking device.

[0038] Based on the availability, performance degradation coefficient and physical parameters of each braking actuator, the maximum braking force that each unit can provide at the current moment is calculated, and the braking forces of all available units are summed to obtain the current theoretical maximum total braking force of the system.

[0039] Dividing the theoretical maximum total braking force by the current total mass of the vehicle yields the theoretical maximum deceleration, without considering road conditions. ;

[0040] Obtain the real-time estimated adhesion coefficient of the current road surface. Calculate the maximum deceleration under adhesion constraints. ,in It is the acceleration due to gravity;

[0041] Take the theoretical maximum deceleration Maximum deceleration under adhesion conditions The smaller value among them is used as the final assessment of the vehicle's maximum safe deceleration. .

[0042] It achieves dynamic adaptive evaluation of deceleration, overcoming the shortcomings of traditional fixed deceleration settings that cannot adapt to load changes, brake wear, and road surface differences. It provides accurate quantitative basis for the determination of serious faults, while ensuring that the deceleration is within a safe and reasonable range during emergency braking, taking into account both braking efficiency and driving stability.

[0043] As a preferred embodiment of the technical solution of this invention, the minimum safe deceleration necessary to maintain the current driving state is dynamically calculated by considering both collision avoidance requirements and speed control requirements. Specific steps include:

[0044] Obtain the relative distance and relative speed between the vehicle and the vehicle in front or an obstacle, and calculate the minimum deceleration required to avoid a collision. ;

[0045] In scenarios involving long downhill slopes or curves, the minimum deceleration required to maintain the target speed is calculated based on the current vehicle speed, the target safe vehicle speed, the road slope angle, and the look-ahead distance. ;

[0046] Find the minimum deceleration required to avoid a collision. Minimum deceleration required to maintain the target vehicle speed and preset reference deceleration The maximum value in the range is used as the minimum safe deceleration necessary to maintain the current driving state. .

[0047] It achieves scenario-based and dynamic adaptation of minimum safe deceleration, avoiding the problem that fixed thresholds cannot meet the safety requirements of different working conditions, providing quantitative standards that fit actual driving scenarios for the determination of serious faults, ensuring the accuracy and safety of the determination results, and improving the system's adaptability to complex operating scenarios.

[0048] As a preferred embodiment of the technical solution of the present invention, S2, from detecting the fault condition to determining the corresponding fault level and triggering the response, includes an anti-interference confirmation process, specifically as follows:

[0049] For the criteria for determining minor and moderate faults, a first confirmation time window is initiated when the criteria are first detected; only when the fault condition continues or accumulates to exceed a first proportional threshold within the first confirmation time window will it be finally determined to enter the corresponding fault level.

[0050] For the criteria for determining a serious fault, when the condition is first detected to be met, a second confirmation time window that is shorter than the first confirmation time window is initiated; only when the fault condition continues to occur within the second confirmation time window is the fault finally determined to be at the serious fault level and a response is immediately triggered.

[0051] Within the first or second confirmation time window, the system maintains the original fault level and corresponding strategy, but continues to record fault events pending confirmation.

[0052] It effectively filters out transient interference, false fault signals such as sensor false alarms, avoids unnecessary responses due to misjudgment, and improves the accuracy of fault diagnosis; at the same time, it adopts a shorter confirmation window for serious faults to ensure timely response in emergency situations, achieves a balance between anti-interference misjudgment and rapid response to emergency faults, and improves the reliability and stability of system redundancy control.

[0053] Secondly, the present invention also provides an adaptive response redundancy control system for longitudinal control of autonomous driving in heavy-duty vehicles, comprising:

[0054] The status monitoring module is used to continuously monitor the working status and performance parameters of the main control path, backup control path, and their associated sensors, actuators, and control units;

[0055] The fault diagnosis and level determination module is communicatively connected to the status monitoring module and is used to determine the current fault level of the system in real time based on the monitored working status and performance parameters. The fault level includes normal working condition, minor fault, moderate fault and severe fault.

[0056] A hierarchical strategy execution module, communicatively connected to the fault diagnosis and level determination module, is used to execute a control strategy corresponding to the fault level based on the real-time determined fault level, wherein:

[0057] When the condition is determined to be normal, the hierarchical strategy execution module is configured to: instruct the main control path to execute longitudinal control, and instruct the backup control path to synchronize the control instructions and vehicle status data in a hot backup manner, and perform periodic deviation verification.

[0058] When a minor fault is determined, the hierarchical strategy execution module is configured to: maintain control of the main control path, and simultaneously instruct the use of sensor data or computing resources of the backup control path to perform real-time verification and compensation of the output of the main control path.

[0059] When a moderate fault is determined, the graded strategy execution module is configured to: within a preset first time threshold, switch the longitudinal control from the main control path to the backup control path, and control the braking force output during the switching process to be no less than a preset first braking force holding threshold.

[0060] When a serious fault is determined, the graded strategy execution module is configured to: activate the emergency fault tolerance mechanism within a preset second time threshold. The emergency fault tolerance mechanism includes at least activating the emergency backup path, limiting the maximum deceleration of the vehicle, and triggering a vehicle warning. The second time threshold is less than the first time threshold.

[0061] The data recording and communication module is used to record fault events, triggered response actions, and related vehicle status and control parameters, and to report them through the vehicle communication network.

[0062] The primary control path and the backup control path are physically or logically isolated from each other.

[0063] As can be seen from the above technical solutions, this application has the following advantages: it changes the rigid logic of traditional master-slave two-state switching, and can take the most appropriate countermeasures according to the actual impact of the fault, thereby maximizing the continuity of autonomous driving, operational efficiency and ride comfort while ensuring functional safety, and avoiding unnecessary degradation or emergency intervention caused by frequent non-critical faults. Attached Figure Description

[0064] To more clearly illustrate the technical solution of this application, the accompanying drawings used in the description will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0065] Figure 1 This is a flowchart illustrating the method provided in an embodiment of the present invention.

[0066] Figure 2 This is a diagram of a redundant system architecture.

[0067] Figure 3 A block diagram of a control system provided in an embodiment of the present invention. Detailed Implementation

[0068] To make the purpose, features, and advantages of this application more apparent and understandable, specific embodiments and accompanying drawings will be used to clearly and completely describe the technical solution protected by this application. Obviously, the embodiments described below are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0069] Unless otherwise defined, all technical and scientific terms used in this application have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used in this application and in the specification of this invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention.

[0070] like Figure 1As shown, this embodiment of the invention provides an adaptive response control method for a redundant longitudinal control system for heavy-duty vehicle autonomous driving, wherein the redundant system is as follows: Figure 2 As shown, it includes at least a primary control path and a backup control path. The method implements a graded response based on a preset fault level, including the following steps:

[0071] S1. Continuously monitor the working status and performance parameters of the main control path, backup control path and their associated sensors, actuators and control units;

[0072] S2. Based on the monitored working status and performance parameters, determine the current fault level of the system in real time. The fault level includes normal working condition, minor fault, moderate fault and severe fault.

[0073] In this embodiment of the invention, the criteria for determining a minor fault include any of the following:

[0074] If the data confidence level of any sensor in the main control path is lower than the first normal operating threshold, in this embodiment of the invention, the data confidence level is calculated through multi-dimensional information fusion and is used to quantify the reliability of individual sensor data. The calculation steps are as follows:

[0075] For each sensor data point, its own diagnostic status is collected synchronously. Data update timestamp and sensor signal strength . The value is typically 1 for normal, 0.5 for warning, and 0 for fault.

[0076] Calculate the time freshness factor , where τ is the effective time constant of sensor data, which is usually set to 2-3 times the sensor data release cycle. The timestamp of the last valid data output by the sensor.

[0077] The current sensor data is compared with measurements of the same target taken by other sensors of the same or different types in the system. Assume there are N other sensors providing valid data. The current sensor data is Then the consistency factor can be calculated as:

[0078] Consistency factor ,in This is the allowable deviation threshold for this physical quantity under typical operating conditions.

[0079] Final data confidence level The weighted fusion yielded:

[0080]

[0081] in, The preset weighting coefficients, and . The value range is [0,1], and the higher the value, the higher the confidence level.

[0082] The first normal operating threshold can be calibrated to 0.7 based on historical data. If it is lower than this value, the data confidence is considered abnormal, triggering a minor fault determination.

[0083] There is a persistent abnormal deviation between the monitoring data of the same physical quantity between the primary control path and the backup control path, and this deviation does not exceed the allowable redundancy verification tolerance; the allowable redundancy verification tolerance is set as follows:

[0084] For key physical quantities, in this embodiment of the invention, these are vehicle speed v, longitudinal acceleration a, and main braking pressure P. Based on vehicle dynamics and sensor characteristics, their confidence intervals under the current operating conditions are established. For example, on a good road surface, the speed calculated based on wheel speed sensors... Speed ​​compared to vision / radar fusion computing The tolerance between them It can be set as follows: .

[0085] For low-adhesion or bumpy roads, relax the tolerances related to wheel speed; for high-temperature environments, relax the tolerances related to pressure sensors.

[0086] The determination of continuous abnormal deviation is triggered only when the deviation continues to exceed the dynamic tolerance for a preset N consecutive control cycles.

[0087] The main control unit's computing resource utilization exceeds the first load threshold affecting the execution of non-critical tasks.

[0088] The criteria for determining a moderate fault include any of the following:

[0089] The actuator response delay of the main control path exceeds the first permissible delay threshold to ensure the longitudinal stability of the vehicle;

[0090] The duration of the communication interruption between the main control unit and the vehicle chassis system responsible for longitudinal control exceeds the first permissible interruption threshold that affects the continuity of control.

[0091] In this embodiment of the invention, a first permissible delay threshold is used to ensure the longitudinal stability of the vehicle. Determined online using vehicle dynamics models:

[0092]

[0093] in: For the allowable range of vehicle speed fluctuations, To reduce the current expected speed, For the maximum permissible yaw rate increment, Current vehicle speed The formula, which defines the vehicle's understeer coefficient, comprehensively determines the maximum allowable execution delay from two dimensions: longitudinal speed control accuracy and lateral stability.

[0094] The first permissible interruption threshold affecting control continuity Set as:

[0095]

[0096] in: For the execution cycle of the vertical controller, This refers to the effective time length set according to the vehicle model that can accurately extrapolate the future state of the vehicle. The fault tolerance coefficient is typically set to 3-5 in this embodiment of the invention. If the communication interruption exceeds this time, the state prediction error will exceed the control allowable range, and therefore it will be judged as a moderate fault.

[0097] The deviation between the braking force output by the main control path and the target value continues to exceed the first permissible deviation threshold that affects tracking accuracy;

[0098] The critical environmental awareness function of the main control path fails, and this function cannot be fully taken over by the awareness system of the backup control path while meeting the control accuracy requirements.

[0099] The criteria for determining a serious fault include any of the following:

[0100] The status and command synchronization channel between the main control unit and the backup control unit has completely failed.

[0101] The braking output capabilities of both the primary control path and the backup control path simultaneously decrease to a level that cannot meet basic braking requirements.

[0102] The maximum safe deceleration of the vehicle, as assessed in real time based on the available resources of the current system, is lower than the minimum safe deceleration necessary to maintain the current driving state.

[0103] The standby status of the emergency backup path used for fault tolerance is unavailable.

[0104] S3. Based on the real-time determined fault level, execute the control strategy corresponding to that level, where:

[0105] When the condition is determined to be normal, the main control path performs longitudinal control, while the backup control path synchronizes control commands and vehicle status data in a hot backup manner and performs periodic deviation checks in preparation for seamless takeover.

[0106] When a minor fault is identified, control of the main control path is maintained, while sensor data or computing resources of the backup control path are used to perform real-time verification and compensation of the output of the main control path to ensure functional safety.

[0107] When a moderate fault is determined, within the preset first time threshold, the longitudinal control is switched from the main control path to the backup control path, and the braking force output is kept not lower than the preset first braking force holding threshold during the switching process.

[0108] When a serious fault is determined, an emergency fault tolerance mechanism is activated within a preset second time threshold. The emergency fault tolerance mechanism includes at least activating an emergency backup path, limiting the maximum deceleration of the vehicle, and triggering a vehicle warning. The second time threshold is less than the first time threshold to ensure that the vehicle enters a controllable deceleration state.

[0109] S4. Record fault events, triggered response actions, and vehicle status and control parameters related to the fault and response, and report them through the vehicle communication network.

[0110] In some embodiments, in the response to a moderate fault, the backup control path is a braking loop independent of the main control path, the first time threshold is set according to vehicle dynamics stability requirements, and the first braking force threshold is a preset target value for braking force retention rate.

[0111] In some embodiments, in response to a severe fault, the emergency fault tolerance mechanism is to switch to a mechanical emergency path, the second time threshold is set according to the urgency of avoiding a collision, and the maximum safe deceleration is limited according to vehicle load and road surface adhesion conditions.

[0112] In this embodiment of the invention, the step of real-time assessment of the vehicle's maximum safe deceleration based on currently available system resources is as follows:

[0113] The availability status and performance degradation coefficient of all braking actuators are acquired and maintained in real time. The braking actuators include at least a line-controlled braking unit for the main control path, an independent hydraulic braking unit for the backup control path, and a non-friction braking device.

[0114] Based on the availability, performance degradation coefficient, and physical parameters of each braking actuator, the maximum braking force that each unit can provide at the current moment is calculated. The braking forces of all available units are then summed to obtain the theoretical maximum total braking force of the system at this moment. ;

[0115] The theoretical maximum total braking force Divide by the current total vehicle mass The theoretical maximum deceleration is obtained without considering road surface conditions. ;

[0116] Obtain the real-time estimated adhesion coefficient of the current road surface. Calculate the maximum deceleration under adhesion constraints. ,in It is the acceleration due to gravity;

[0117] Take the theoretical maximum deceleration With attachment-limited deceleration The smaller value among them is used as the final assessment of the vehicle's maximum safe deceleration. ,Right now: .

[0118] The minimum safe deceleration necessary to maintain the current driving state is dynamically calculated by combining collision avoidance requirements and speed control requirements. The specific steps include:

[0119] Get the relative distance between your vehicle and the vehicle in front or an obstacle. With relative velocity Calculate the minimum deceleration required to avoid a collision. The calculation formula is: ,in This is a preset safety distance margin;

[0120] In scenarios involving long downhill slopes or curves, based on the current vehicle speed Target safe speed Road slope angle and forward distance Calculate the minimum deceleration required to maintain the target vehicle speed. The calculation formula is: It should be noted that the required look-ahead distance The determination is made dynamically based on the current vehicle status and driving scenario. In one embodiment, a model based on a constant look-ahead time is used, i.e. ,in In this embodiment of the invention, the pre-calibrated time constant is set to 2.5 seconds. In another embodiment, The upper-level motion planning module generates the parameters in real time based on high-precision maps and traffic environment information, and sends them to this control system as one of the target parameters.

[0121] Collision avoidance requires deceleration Minimum deceleration required to maintain the target vehicle speed and preset reference deceleration The maximum value in the range is used as the minimum safe deceleration necessary to maintain the current driving state. .

[0122] In some embodiments, S2, from detecting the fault condition to determining the corresponding fault level and triggering the response, includes an anti-interference confirmation process, specifically:

[0123] For the criteria for determining minor and moderate faults, a first confirmation time window is initiated when the criteria are first detected; only when the fault condition continues or accumulates to exceed a first proportional threshold within the first confirmation time window will it be finally determined to enter the corresponding fault level.

[0124] For the criteria for determining a serious fault, when the condition is first detected to be met, a second confirmation time window that is shorter than the first confirmation time window is initiated; only when the fault condition continues to occur within the second confirmation time window is the fault finally determined to be at the serious fault level and a response is immediately triggered.

[0125] Within the first or second confirmation time window, the system maintains the original fault level and corresponding strategy, but continues to record fault events pending confirmation.

[0126] like Figure 3 As shown, this embodiment of the invention also provides an adaptive response redundancy control system for longitudinal control of heavy-duty vehicle autonomous driving, comprising:

[0127] The status monitoring module is used to continuously monitor the working status and performance parameters of the main control path, backup control path, and their associated sensors, actuators, and control units;

[0128] The fault diagnosis and level determination module is communicatively connected to the status monitoring module and is used to determine the current fault level of the system in real time based on the monitored working status and performance parameters. The fault level includes normal working condition, minor fault, moderate fault and severe fault.

[0129] A hierarchical strategy execution module, communicatively connected to the fault diagnosis and level determination module, is used to execute a control strategy corresponding to the fault level based on the real-time determined fault level, wherein:

[0130] When the condition is determined to be normal, the hierarchical strategy execution module is configured to: instruct the main control path to execute longitudinal control, and instruct the backup control path to synchronize the control instructions and vehicle status data in a hot backup manner, and perform periodic deviation verification.

[0131] When a minor fault is determined, the hierarchical strategy execution module is configured to: maintain control of the main control path, and simultaneously instruct the use of sensor data or computing resources of the backup control path to perform real-time verification and compensation of the output of the main control path.

[0132] When a moderate fault is determined, the graded strategy execution module is configured to: within a preset first time threshold, switch the longitudinal control from the main control path to the backup control path, and control the braking force output during the switching process to be no less than a preset first braking force holding threshold.

[0133] When a serious fault is determined, the graded strategy execution module is configured to: activate the emergency fault tolerance mechanism within a preset second time threshold. The emergency fault tolerance mechanism includes at least activating the emergency backup path, limiting the maximum deceleration of the vehicle, and triggering a vehicle warning. The second time threshold is less than the first time threshold.

[0134] The data recording and communication module is used to record fault events, triggered response actions, and related vehicle status and control parameters, and to report them through the vehicle communication network.

[0135] The primary control path and the backup control path are physically or logically isolated from each other.

[0136] In some embodiments, the fault diagnosis and severity determination module is configured to determine a minor fault when any of the following conditions occur:

[0137] The confidence level of data from any sensor in the main control path is lower than the first normal operating threshold.

[0138] There is a continuous abnormal deviation between the monitoring data of the same physical quantity between the main control path and the backup control path, and the deviation does not exceed the allowable redundancy verification tolerance.

[0139] The main control unit's computing resource utilization exceeds the first load threshold affecting the execution of non-critical tasks.

[0140] In some embodiments, the fault diagnosis and severity determination module is configured to determine a moderate fault when any of the following conditions occur:

[0141] The actuator response delay of the main control path exceeds the first permissible delay threshold to ensure the longitudinal stability of the vehicle;

[0142] The duration of the communication interruption between the main control unit and the vehicle chassis system responsible for longitudinal control exceeds the first permissible interruption threshold that affects the continuity of control.

[0143] The deviation between the braking force output by the main control path and the target value continues to exceed the first permissible deviation threshold that affects tracking accuracy;

[0144] The critical environmental awareness function of the main control path fails, and this function cannot be fully taken over by the awareness system of the backup control path while meeting the control accuracy requirements.

[0145] In some embodiments, the fault diagnosis and severity determination module is configured to determine a serious fault when any of the following conditions occur:

[0146] The status and command synchronization channel between the main control unit and the backup control unit has completely failed.

[0147] The braking output capabilities of both the primary control path and the backup control path simultaneously decrease to a level that cannot meet basic braking requirements.

[0148] The maximum safe deceleration of the vehicle, as assessed in real time based on the available resources of the current system, is lower than the minimum safe deceleration necessary to maintain the current driving state.

[0149] The standby status of the emergency backup path used for fault tolerance is unavailable.

[0150] In some embodiments, a safety boundary assessment module is also included for real-time assessment of the vehicle’s maximum safe deceleration and the required minimum safe deceleration.

[0151] The security boundary assessment module is configured as follows:

[0152] (a) The availability status and performance degradation coefficient of all braking actuators are acquired and maintained in real time. Based on this, the current theoretical maximum total braking force of the system is calculated, and the maximum safe deceleration of the vehicle is evaluated by combining the total mass of the vehicle and the current road surface estimated adhesion coefficient.

[0153] (b) Based on environmental perception information, calculate the minimum deceleration required to avoid a collision and the minimum deceleration required to maintain the target vehicle speed, and combine the preset benchmark deceleration to determine the minimum safe deceleration necessary to maintain the current driving state.

[0154] In some embodiments, the fault diagnosis and level determination module includes an anti-interference confirmation logic unit;

[0155] The anti-interference confirmation logic unit is configured as follows:

[0156] For conditions that trigger the determination of minor or moderate faults, a first confirmation time window is started for continuous confirmation. The final determination result is only output when the condition continuously or cumulatively meets the preset proportion within the window.

[0157] For conditions that trigger a critical fault determination, a shorter second confirmation window is initiated for immediate confirmation. The final determination result is output and a response is triggered only if the condition is continuously met within this window.

[0158] In some embodiments, the backup control path includes a hydraulic braking circuit independent of the main control path line control braking unit; the emergency backup path is an emergency braking cable or push rod device mechanically connected to the brake pedal.

[0159] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions in the embodiments of the present invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium such as a USB flash drive, mobile hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, or other media capable of storing program code. It includes several instructions to cause a computer terminal (which may be a personal computer, server, or a second terminal, network terminal, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0160] In the embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0161] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0162] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0163] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An adaptive response control method for a redundant longitudinal control system for autonomous driving of heavy-duty vehicles, wherein the redundant system includes at least a primary control path and a backup control path, characterized in that, The method implements a graded response based on a preset fault level, including the following steps: S1. Continuously monitor the working status and performance parameters of the main control path, backup control path and their associated sensors, actuators and control units; S2. Based on the monitored working status and performance parameters, determine the current fault level of the system in real time. The fault level includes normal working condition, minor fault, moderate fault and severe fault. S3. Based on the real-time determined fault level, execute the control strategy corresponding to that fault level, wherein: When the condition is determined to be normal, the main control path performs longitudinal control, while the backup control path synchronizes control commands and vehicle status data in a hot backup manner and performs periodic deviation checks. When a minor fault is identified, control of the main control path is maintained, while sensor data or computing resources of the backup control path are used to perform real-time verification and compensation of the output of the main control path to ensure functional safety. When a moderate fault is determined, within the preset first time threshold, the longitudinal control is switched from the main control path to the backup control path, and the braking force output is kept not lower than the preset first braking force holding threshold during the switching process. When a serious fault is determined, an emergency fault tolerance mechanism is activated within a preset second time threshold. The emergency fault tolerance mechanism includes at least activating an emergency backup path, limiting the maximum deceleration of the vehicle, and triggering a vehicle warning. The second time threshold is less than the first time threshold to ensure that the vehicle enters a controllable deceleration state. S4. Record fault events, triggered response actions, and vehicle status and control parameters related to the fault and response, and report them through the vehicle communication network.

2. The adaptive response control method for a redundant longitudinal control system for automatic driving of heavy-duty vehicles according to claim 1, characterized in that, The criteria for determining a minor fault include any of the following: The confidence level of data from any sensor in the main control path is lower than the first normal operating threshold. There is a continuous abnormal deviation between the monitoring data of the same physical quantity between the main control path and the backup control path, and the deviation does not exceed the allowable redundancy verification tolerance. The main control unit's computing resource utilization exceeds the first load threshold affecting the execution of non-critical tasks.

3. The adaptive response control method for a redundant longitudinal control system for automatic driving of heavy-duty vehicles according to claim 2, characterized in that, The criteria for determining a moderate fault include any of the following: The actuator response delay of the main control path exceeds the first permissible delay threshold to ensure the longitudinal stability of the vehicle; The duration of the communication interruption between the main control unit and the vehicle chassis system responsible for longitudinal control exceeds the first permissible interruption threshold that affects the continuity of control. The deviation between the braking force output by the main control path and the target value continues to exceed the first permissible deviation threshold that affects tracking accuracy; The critical environmental awareness function of the main control path fails, and this function cannot be fully taken over by the awareness system of the backup control path while meeting the control accuracy requirements.

4. The adaptive response control method for a redundant longitudinal control system for autonomous driving of heavy-duty vehicles according to claim 3, characterized in that, The criteria for determining a serious fault include any of the following: The status and command synchronization channel between the main control unit and the backup control unit has completely failed. The braking output capabilities of both the primary control path and the backup control path simultaneously decrease to a level that cannot meet basic braking requirements. The maximum safe deceleration of the vehicle, as assessed in real time based on the available resources of the current system, is lower than the minimum safe deceleration necessary to maintain the current driving state. The standby status of the emergency backup path used for fault tolerance is unavailable.

5. The adaptive response control method for a redundant longitudinal control system for automatic driving of heavy-duty vehicles according to claim 4, characterized in that, In the response to a moderate fault, the backup control path is a braking loop independent of the main control path. The first time threshold is set according to the vehicle dynamics stability requirements, and the first braking force threshold is a preset target value for braking force retention rate.

6. The adaptive response control method for a redundant longitudinal control system for automatic driving of heavy-duty vehicles according to claim 4, characterized in that, In response to severe malfunctions, the emergency fault tolerance mechanism switches to the mechanical emergency path, the second time threshold is set according to the urgency of avoiding a collision, and the maximum safe deceleration is limited according to the vehicle load and road adhesion conditions.

7. The adaptive response control method for a redundant longitudinal control system for automatic driving of heavy-duty vehicles according to claim 1, characterized in that, The steps for real-time assessment of the vehicle's maximum safe deceleration based on currently available system resources: The availability status and performance degradation coefficient of all braking actuators are acquired and maintained in real time. The braking actuators include at least a line-controlled braking unit for the main control path, an independent hydraulic braking unit for the backup control path, and a non-friction braking device. Based on the availability, performance degradation coefficient and physical parameters of each braking actuator, the maximum braking force that each unit can provide at the current moment is calculated, and the braking forces of all available units are summed to obtain the current theoretical maximum total braking force of the system. Dividing the theoretical maximum total braking force by the current total mass of the vehicle yields the theoretical maximum deceleration, without considering road conditions. ; Obtain the real-time estimated adhesion coefficient of the current road surface. Calculate the maximum deceleration under adhesion constraints. ,in It is the acceleration due to gravity; Take the theoretical maximum deceleration Maximum deceleration under adhesion conditions The smaller value among them is used as the final assessment of the vehicle's maximum safe deceleration. .

8. The adaptive response control method for a longitudinal control redundancy system for automatic driving of heavy-duty vehicles according to claim 7, characterized in that, The minimum safe deceleration necessary to maintain the current driving state is dynamically calculated by combining collision avoidance requirements and speed control requirements. The specific steps include: Obtain the relative distance and relative speed between the vehicle and the vehicle in front or an obstacle, and calculate the minimum deceleration required to avoid a collision. ; In scenarios involving long downhill slopes or curves, the minimum deceleration required to maintain the target speed is calculated based on the current vehicle speed, the target safe vehicle speed, the road slope angle, and the look-ahead distance. ; Find the minimum deceleration required to avoid a collision. Minimum deceleration required to maintain the target vehicle speed and preset reference deceleration The maximum value in the range is used as the minimum safe deceleration necessary to maintain the current driving state. .

9. The adaptive response control method for a longitudinal control redundancy system for automatic driving of heavy-duty vehicles according to claim 4, characterized in that, In S2, the process from detecting the fault condition to determining the corresponding fault level and triggering a response includes an anti-interference confirmation process, specifically: For the criteria for determining minor and moderate faults, a first confirmation time window is initiated when the criteria are first detected; only when the fault condition continues or accumulates to exceed a first proportional threshold within the first confirmation time window will it be finally determined to enter the corresponding fault level. For the criteria for determining a serious fault, when the condition is first detected to be met, a second confirmation time window that is shorter than the first confirmation time window is initiated; only when the fault condition continues to occur within the second confirmation time window is the fault finally determined to be at the serious fault level and a response is immediately triggered. Within the first or second confirmation time window, the system maintains the original fault level and corresponding strategy, but continues to record fault events pending confirmation.

10. An adaptive response redundancy control system for longitudinal control of autonomous driving in heavy-duty vehicles, characterized in that, include: The status monitoring module is used to continuously monitor the working status and performance parameters of the main control path, backup control path, and their associated sensors, actuators, and control units; The fault diagnosis and level determination module is communicatively connected to the status monitoring module and is used to determine the current fault level of the system in real time based on the monitored working status and performance parameters. The fault level includes normal working condition, minor fault, moderate fault and severe fault. A hierarchical strategy execution module, communicatively connected to the fault diagnosis and level determination module, is used to execute a control strategy corresponding to the fault level based on the real-time determined fault level, wherein: When the condition is determined to be normal, the hierarchical strategy execution module is configured to: instruct the main control path to execute longitudinal control, and instruct the backup control path to synchronize the control instructions and vehicle status data in a hot backup manner, and perform periodic deviation verification. When a minor fault is determined, the hierarchical strategy execution module is configured to: maintain control of the main control path, and simultaneously instruct the use of sensor data or computing resources of the backup control path to perform real-time verification and compensation of the output of the main control path. When a moderate fault is determined, the graded strategy execution module is configured to: within a preset first time threshold, switch the longitudinal control from the main control path to the backup control path, and control the braking force output during the switching process to be no less than a preset first braking force holding threshold. When a serious fault is determined, the graded strategy execution module is configured to: activate the emergency fault tolerance mechanism within a preset second time threshold. The emergency fault tolerance mechanism includes at least activating the emergency backup path, limiting the maximum deceleration of the vehicle, and triggering a vehicle warning. The second time threshold is less than the first time threshold. The data recording and communication module is used to record fault events, triggered response actions, and related vehicle status and control parameters, and to report them through the vehicle communication network. The primary control path and the backup control path are physically or logically isolated from each other.

Citation Information

Patent Citations

  • Safety control method of automatic driving automobile, electronic equipment and storage medium

    CN111874001A

  • Redundancy control method of automatic driving system, automatic driving system, automobile, controller and computer readable storage medium

    CN112373477A