Vehicle formation communication and emergency management system and method

By constructing an in-vehicle self-organizing Wi-Fi Mesh network to concurrently transmit high-bandwidth data streams and low-latency control streams, combined with autonomous emergency management, the contradiction between high bandwidth and low latency in vehicle platooning communication is resolved, providing reliable autonomous security and avoiding the risk of loss of control due to communication failure.

CN121583084APending Publication Date: 2026-02-27SHANGHAI INTELLIGENT & CONNECTED VEHICLE R & D CENTER CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511559065.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-29
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

Existing vehicle platooning communication technologies cannot simultaneously handle high-bandwidth data transmission and low-latency command response during remote takeover, and lack reliable autonomous emergency safety mechanisms in the event of communication link deterioration or interruption, leading to traffic safety risks.

Method used

A self-organizing Wi-Fi Mesh network is constructed in the vehicle, which adopts a priority transmission mechanism to transmit remote monitoring and vehicle control data streams concurrently. When the communication link status is below a threshold, the subordinate vehicle unit will autonomously trigger safety operations, including speed limiting and braking.

Benefits of technology

It enables high-bandwidth, low-latency remote takeover, ensuring the autonomous safety of vehicles when communication links deteriorate or are interrupted, avoiding the risk of loss of control, and improving communication robustness and coverage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121583084A_ABST
    Figure CN121583084A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle formation communication and emergency management system and method, and belongs to the technical field of intelligent traffic and Internet of Vehicles. The invention aims to solve the problems that high-bandwidth data transmission and low-delay instruction response cannot be considered at the same time and an autonomous emergency safety mechanism is lacked when communication is interrupted in the prior art. According to the system and the method, a master control vehicle-mounted unit and a slave vehicle-mounted unit jointly construct a vehicle-mounted self-organizing Wi-Fi Mesh network; based on a preset priority, concurrently transmitting a first data stream for remote monitoring and a second data stream for vehicle control, the priority of the second data stream being higher than that of the first data stream; the slave vehicle-mounted unit monitors the state of a communication link between the slave vehicle-mounted unit and the master control vehicle-mounted unit, and when the communication state is lower than a preset threshold value, preset safety operation including safety braking is triggered autonomously. According to the invention, both high bandwidth and low delay can be considered, autonomous fault protection is provided, and the real-time performance and safety of remote takeover are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of intelligent transportation and vehicle networking technologies, and in particular to a vehicle platooning communication and emergency management system and method. Background Technology

[0002] In autonomous vehicle platooning, especially in scenarios involving remote takeover, inter-vehicle communication is a critical technology. Currently, inter-vehicle communication solutions mainly rely on cellular vehicle-to-everything (V2X) technology. This technology is primarily designed for broadcast-based basic safety messages, and its inherent bandwidth and latency characteristics make it difficult to meet the requirements of real-time transmission of multiple high-definition videos and millisecond-level control command responses needed for remote takeover.

[0003] To address these issues, some technologies have proposed using localized, self-organizing mesh networks to enhance inter-vehicle communication capabilities. These networks, through multi-hop forwarding between nodes, can provide higher local bandwidth and stronger link robustness than cellular networks. However, existing vehicular mesh network solutions still have significant drawbacks: First, they are typically not optimized for the transmission of mixed data streams in the specific scenario of remote takeover. Specifically, they lack effective quality of service mechanisms to differentiate and prioritize latency-sensitive remote control commands and bandwidth-intensive high-definition video streams, resulting in a failure to guarantee the real-time performance of critical control commands under high network load. Second, these solutions generally lack an independent, autonomous emergency safety mechanism built into the subordinate vehicles. When the communication link between vehicles deteriorates or is completely interrupted due to signal interference, obstruction, or other reasons, the remotely controlled subordinate vehicles lack a clear protocol to automatically enter a safe state, potentially leading to loss of vehicle control and posing a serious traffic safety risk.

[0004] Therefore, there is an urgent need in this field for a new technical solution that can not only provide high-bandwidth, low-latency local communication capabilities, but also ensure the real-time nature of remote takeover operations and security in extreme situations through intelligent transmission scheduling and autonomous emergency management. Summary of the Invention

[0005] The purpose of this application is to provide a vehicle platooning communication and emergency management system and method, which aims to solve the technical problems of existing vehicle platooning communication technologies in supporting remote takeover, which cannot simultaneously ensure high-bandwidth data transmission and low-latency command response, and lack a reliable autonomous emergency safety guarantee mechanism when the communication link deteriorates or is interrupted.

[0006] To achieve the above objectives, this application provides a vehicle platoon communication and emergency management system, applied to a vehicle platoon consisting of at least one lead vehicle and one or more subordinate vehicles. The system includes a master control vehicle-mounted unit installed on the lead vehicle and subordinate vehicle-mounted units installed on the subordinate vehicles. The master control vehicle-mounted unit and the subordinate vehicle-mounted units are configured to jointly construct an in-vehicle self-organizing Wi-Fi Mesh network. The system is configured to concurrently transmit, based on a preset priority, a first data stream for remote monitoring and a second data stream for vehicle control, wherein the transmission priority of the second data stream is higher than that of the first data stream. The subordinate vehicle-mounted units are configured to monitor the communication link status with the master control vehicle-mounted unit and autonomously trigger preset safety operations when the communication link status falls below a preset threshold.

[0007] Optionally, the system is configured to comply with WMM Quality of Service standards to map the second data stream to the highest priority voice access class AC_VO for transmission.

[0008] Optionally, the master vehicle unit is configured to periodically send a heartbeat signal; the slave vehicle unit determines the communication link status by monitoring the reception of the heartbeat signal.

[0009] Optionally, the safety operation includes a tiered emergency response; the subordinate vehicle unit is configured to: execute a level one response to limit the speed of the subordinate vehicle when the communication link status is worse than a first threshold; and execute a level two response to decelerate the subordinate vehicle to a stop when the communication link status is worse than a second threshold.

[0010] Optionally, both the master control vehicle unit and the slave vehicle unit are equipped with a multi-antenna system, which adopts spatial diversity and polarization diversity design.

[0011] To achieve the above objectives, this application also provides a vehicle platoon communication and emergency management method, applicable to a vehicle platoon consisting of at least one lead vehicle and one or more subordinate vehicles. The method is executed by a master control vehicle-mounted unit installed in the lead vehicle and subordinate vehicle-mounted units installed in the subordinate vehicles, and includes the following steps: constructing an in-vehicle self-organizing Wi-Fi Mesh network; concurrently transmitting a first data stream for remote monitoring and a second data stream for vehicle control based on a preset priority, wherein the transmission priority of the second data stream is higher than that of the first data stream; the subordinate vehicle-mounted units monitoring the communication link status with the master control vehicle-mounted unit, and autonomously performing preset safety operations when the communication link status is below a preset threshold.

[0012] Optionally, the step of concurrently transmitting the first data stream and the second data stream includes: following the WMM Quality of Service standard, mapping the second data stream to the highest priority voice access category AC_VO for transmission.

[0013] Optionally, the step of monitoring the communication link status includes: the subordinate vehicle unit receiving a heartbeat signal periodically sent by the master vehicle unit, and determining the communication link status based on the reception of the heartbeat signal.

[0014] Optionally, the steps of autonomously executing preset safety operations include: when the communication link status is worse than a first threshold, executing a first-level response to limit the speed of the subordinate vehicle; and when the communication link status is worse than a second threshold, executing a second-level response to decelerate the subordinate vehicle to a stop.

[0015] Optionally, the step of concurrently transmitting the first data stream and the second data stream includes: transmitting and receiving wireless signals using spatial diversity and polarization diversity techniques.

[0016] Compared with the prior art, the technical solution provided in this application has the following beneficial effects: 1. Balancing bandwidth and latency for high-fidelity remote control. By constructing a localized in-vehicle self-organizing Wi-Fi Mesh network, a foundation for high-bandwidth data transmission is provided. At the same time, by setting different transmission priorities for different data streams, it ensures that latency-sensitive vehicle control commands are transmitted first, resolving the contradiction that existing technologies cannot simultaneously meet the requirements of high bandwidth and low latency, and achieving precise and real-time remote control.

[0017] 2. Significantly enhances safety and provides autonomous fault protection. By having the subordinate onboard unit autonomously monitor the communication link status and automatically trigger preset safety operations, including safe braking, when communication deteriorates or is interrupted, the subordinate vehicle possesses the ability to autonomously avoid risks in extreme situations. This prevents serious accidents caused by loss of vehicle control due to communication failure and provides reliable localized fault safety assurance.

[0018] 3. Enhanced communication robustness and coverage. Based on the self-organizing mesh network architecture, when direct communication between nodes is blocked, data can be forwarded through intermediate vehicle nodes via multiple hops, effectively overcoming signal fading problems in long-distance or non-line-of-sight communication scenarios, and enhancing the self-healing capability and overall coverage of the internal communication network of the formation. Attached Figure Description

[0019] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1This is a schematic diagram of the system architecture and hybrid network topology provided for embodiments of this application.

[0020] Figure 2 This is a schematic diagram of the data transmission and QoS scheduling process provided in the embodiments of this application.

[0021] Figure 3 A schematic diagram of the state transition of the hierarchical emergency management mechanism provided in the embodiments of this application.

[0022] Figure 4 This is a schematic diagram of a preferred vehicle-mounted antenna arrangement provided in an embodiment of this application.

[0023] Figure 5 A flowchart illustrating the method provided in an embodiment of this application.

[0024] Figure 6 Signaling interaction timing diagram for the method embodiment provided in this application. Detailed Implementation

[0025] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the protection scope of the present invention.

[0026] System composition and hardware configuration (see) Figure 1 and Figure 4 ) The system of the present invention consists of a master control vehicle-mounted unit 101 deployed on the lead vehicle of the formation and slave vehicle-mounted units 102 and 103 deployed on multiple subordinate vehicles. All units together constitute a Wi-Fi Mesh network 100.

[0027] Each vehicle-mounted unit is equipped with an industrial-grade Wi-Fi 6 (IEEE 802.11ax) communication module with a transmit power of no less than +25 dBm, supporting OFDMA, MU-MIMO and 1024-QAM technologies.

[0028] To overcome the signal shielding and multipath fading effects of the vehicle's metal casing, a preferred antenna arrangement scheme is adopted. Figure 4 A 5-7 dBi omnidirectional high-gain antenna (401, 402, 403, 404) is installed at each of the four corners of the roof of each vehicle, forming a 4x4 MIMO configuration. To achieve polarization diversity, antennas 401 and 403 are vertically polarized, while antennas 402 and 404 are horizontally polarized. This scheme provides stable 360-degree signal coverage without dead zones.

[0029] Network construction and data transmission (see Figure 1 and Figure 2 ) When the platoon is established, each vehicle unit automatically performs node discovery and WPA3-SAE security authentication after power-on, forming a dynamic mesh network. The network topology (100) is a hybrid of chain and mesh. During normal operation, data is mainly transmitted along the chain path 105. When direct communication between vehicle 103 and the platoon leader 101 is blocked, data can be forwarded via multiple hops through vehicle 102 as a relay 106, ensuring the robustness of the link. The network routing protocol adopts the optimized AODV protocol, which comprehensively evaluates signal strength (RSSI), signal-to-noise ratio (SNR), and link delay to select the optimal forwarding path.

[0030] At the data transmission level ( Figure 2 The system strictly adheres to the WMM (Wideband Management Model) service quality standard. When the master control unit issues a remote control command 201 or a "heartbeat" signal, the processor encapsulates it into the highest priority AC_VO voice access category 202 to ensure absolute priority in wireless channel contention and achieve the lowest latency transmission. High-definition video streams 203 collected by subordinate vehicles are encapsulated into the second-highest priority AC_VI video access category 204. Regular vehicle status data 205, such as speed and GPS location, are encapsulated into the normal priority AC_BE best-effort category 206. All data streams are uniformly scheduled at the MAC layer 207 and then sent out through the physical layer 208.

[0031] Emergency management mechanism (see) Figure 3 ) The core security feature of this invention is its tiered emergency management mechanism, whose state transition process is as follows: Figure 3 As shown.

[0032] 1. Normal operating state 301: In this state, the slave vehicle can stably receive the encrypted "heartbeat" signal broadcast by the master control unit at a frequency of 10 Hz, and the end-to-end delay of control commands is less than 200ms, with a critical command packet loss rate of less than 15%. The vehicle is fully subject to remote control.

[0033] 2. Trigger condition monitoring: The subordinate unit continuously monitors multiple trigger conditions.

[0034] ○Condition A (305): Within a 1-second sliding window, the control command delay is consistently higher than 200ms or the packet loss rate is higher than 15%.

[0035] ○Condition B 306: No valid "heartbeat" signal is received within a preset time window of 500ms, or the vehicle's underlying controller reports three consecutive failures in remote command execution.

[0036] 3. Level 1 Emergency Response 302: When only condition A is triggered, the system enters Level 1 response status. In this state, the vehicle still accepts remote control, but the maximum speed is automatically limited to 5 km / h, and a communication quality degradation warning is sent to the main control unit. If communication is restored, it returns to normal operation status 301.

[0037] 4. Level 2 Emergency Response 303: When condition B is triggered, or if communication deteriorates further under Level 1 response status, the system immediately enters Level 2 response status and executes a safety shutdown procedure. This procedure includes: Immediately revoke remote control privileges and ignore all subsequent commands.

[0038] ○ Automatic braking with a gentle deceleration of 1.5 m / s².

[0039] ○After the vehicle comes to a complete stop, the electronic parking brake will automatically engage and the hazard warning lights (double flashers) will be activated.

[0040] 5. Safety Standby State 304: After the vehicle has come to a safe stop, it enters this state and waits for on-site personnel to intervene manually or for the system to be restarted.

[0041] Through the above mechanism, the present invention ensures that even in the extreme case of complete communication interruption, the controlled vehicle can automatically and safely transition to a stationary state, thereby avoiding the risk of loss of control.

[0042] This invention has the following significant advantages: 1. High bandwidth: It can provide a stable uplink bandwidth of 20-50 Mbps for a single vehicle, and supports the concurrent transmission of multiple 1080p high-definition video streams, which greatly improves the remote monitoring and environmental awareness capabilities.

[0043] 2. Low latency: Through strict QoS priority scheduling, the end-to-end average latency of critical remote control commands is controlled within 50ms, enabling precise and real-time remote takeover of vehicles.

[0044] 3. High Reliability: The self-organizing Mesh architecture provides robust network redundancy and self-healing capabilities. When direct communication between nodes is blocked, data can be forwarded via intermediate vehicles through multiple hops, effectively solving long-distance or non-line-of-sight communication problems. The platoon communication distance can be extended to hundreds of meters.

[0045] 4. High Security: An independent emergency management mechanism based on "heartbeat" signals, coupled with clear and quantifiable trigger conditions and tiered response strategies, ensures that the controlled vehicle can automatically enter a safe state in extreme cases of communication link failure, effectively preventing safety accidents. Meanwhile, WPA3 and AES-256 dual-layer encryption mechanisms guarantee the confidentiality and integrity of communications.

[0046] Example 1 This embodiment provides a complete implementation scheme for a vehicle platoon communication and emergency management system and method, which aims to meet the urgent needs of vehicle platoons for high-bandwidth video backhaul and low-latency concurrent transmission of control commands in remote takeover scenarios, and to provide autonomous security guarantees in extreme situations such as communication link interruption.

[0047] Please see Figure 1 This document illustrates the system architecture and network topology of one embodiment of this application. In this embodiment, the system is applied to a vehicle platoon consisting of a lead vehicle and three subordinate vehicles, employing a routing protocol that optimizes the routing. The system includes a master control on-board unit 101 mounted on the lead vehicle, and subordinate on-board units 102, 103, and 104 mounted on the three subordinate vehicles. Physically, each on-board unit (including the master control on-board unit 101 and the subordinate on-board units 102, 103, and 104) is a highly integrated embedded computing and communication platform. Specifically, the core hardware of each unit may include a high-performance multi-core processor, such as an industrial-grade system-on-a-chip with at least four processing cores and a clock speed of at least 2.0 GHz, used to execute complex network protocol stacks, data encryption / decryption, quality of service scheduling, and emergency management logic.

[0048] To achieve high-speed wireless communication, each unit integrates an industrial-grade wireless communication module supporting the IEEE 802.11ax standard. This module features high transmit power (e.g., a total transmit power of no less than +25 dBm within regulatory limits) and high receive sensitivity (e.g., sensitivity better than -95 dBm at the lowest data rate) to ensure link budget for long-distance communication. For interaction with the vehicle's underlying control system, each unit is also equipped with at least one high-speed controller area network (CAN) bus interface for reading vehicle status information such as vehicle speed, wheel speed, and steering wheel angle, and for issuing control commands to actuators such as the vehicle's electronic stability control system or brake-by-wire system. Furthermore, to meet the video monitoring requirements for remote takeover, each subordinate vehicle unit 102, 103, and 104 is also equipped with multiple high-definition video acquisition interfaces, capable of simultaneously accessing and processing, for example, at least four 1080p resolution, 30 frames per second video camera data streams.

[0049] Please refer to the following: Figure 4To maximize the stability and reliability of wireless communication, this embodiment employs an optimized multi-antenna system. Specifically, each on-board unit is equipped with four antennas, forming a 4x4 multiple-input multiple-output system. For example... Figure 4 As shown, these four antennas are strategically positioned at the four corners of the vehicle's roof, corresponding to antenna mounting positions 401, 402, 403, and 404. This arrangement first achieves spatial diversity by increasing the physical spacing between the antennas, effectively combating fast signal fading caused by multipath effects. Building upon this, this embodiment also introduces polarization diversity design. Specifically, the antennas located diagonally across the vehicle employ mutually orthogonal polarization; for example, the antennas mounted at positions 401 and 403 are vertically polarized antennas, while those at positions 402 and 404 are horizontally polarized antennas. Since the polarization direction of a wireless signal changes during propagation and reflection, simultaneously receiving signal components in both vertical and horizontal polarization directions significantly reduces signal loss due to polarization mismatch, thereby providing a more robust communication link in complex urban canyons or non-line-of-sight environments. It is understood that this multi-antenna design, combining spatial diversity and polarization diversity, is a crucial physical layer foundation for achieving the high-reliability communication described in this application.

[0050] Please refer to it again. Figure 1 and combined Figure 5 The flowchart of the method is shown. A core component of the system and method described in this embodiment is the construction of a localized vehicular ad hoc network. After the vehicle is powered on, the main control vehicular unit 101 and all subordinate vehicular units 102, 103, and 104 execute step S501, which involves starting and initializing the communication unit. After initialization, each unit proceeds to step S502, which involves scanning and joining the Wi-Fi Mesh network. In this step, the Wi-Fi 6 communication module of each unit begins broadcasting beacon frames on a preset channel to declare its presence and networking intent. When a unit receives a beacon frame from another unit, they complete mutual authentication and session key negotiation through a secure peer-to-peer authentication protocol, namely the core mechanism of the WPA3 security protocol. This protocol effectively resists offline dictionary attacks, ensuring that only authorized vehicles with pre-configured identical credentials can join the network.

[0051] After successful authentication, these vehicle-mounted units collectively form a logically unified Wi-Fi Mesh network 100 encrypted with Advanced Encryption Standard (AES). This network is independent of any public cellular network infrastructure, providing a dedicated, highly secure communication environment within the platoon. In this network, all vehicle-mounted units act as network nodes, capable of sending and receiving their own data, and also acting as routers to forward data to other nodes. In this embodiment, the network layer routing protocol employs an optimized On-Demand Distance Vector (AODV) protocol. This protocol, when selecting a route path, does not only consider hop count but also comprehensively evaluates multiple link quality metrics, including received signal strength indication, signal-to-noise ratio (SNR), and link round-trip time (RTD) measured via probe packets. These metrics are then combined into a comprehensive path cost using a weighted function, thereby selecting the truly "optimal" path, rather than simply the "shortest" path. This dynamic routing mechanism allows for flexible and adaptable network topologies, such as… Figure 1 As shown, a chain path 105 can be formed for sequential transmission along the vehicle platoon, or a multi-hop forwarding path 106 can be formed by relaying through intermediate nodes (such as subordinate vehicle units 102 and 103) when the direct link (such as between the master control vehicle unit 101 and the subordinate vehicle unit 104) is blocked or of poor quality. Correspondingly, this self-organizing and self-healing characteristic greatly enhances the robustness of the entire platoon communication.

[0052] Once the network is built, the system enters a continuous data transmission and monitoring cycle, that is... Figure 5 The process begins with the data transmission and reception step S503. In a remote takeover scenario, the system needs to concurrently process multiple data streams with drastically different quality of service (QoS) requirements. To address the channel contention issue between high-bandwidth video streams and low-latency control commands, this embodiment utilizes the QoS guarantee mechanism defined in the Wi-Fi 6 standard, particularly the Wi-Fi Multimedia Specification.

[0053] Please see Figure 2 It details the data transmission and quality of service scheduling process. In this embodiment, all data to be transmitted is divided into at least three categories. The first category is a second data stream for vehicle control, specifically including remote control commands sent from the master control vehicle unit 101 to the subordinate vehicles, and periodic "heartbeat" signals used to maintain link activity monitoring. Figure 2This is uniformly represented as Remote Control Command / Heartbeat 201. Such data is extremely sensitive to latency; even a slight delay can affect the accuracy and security of control. Therefore, during data encapsulation, the Differential Service Code Point field in the IP header of these packets is marked with the highest priority. Subsequently, in the Media Access Control layer 207, they are mapped to the highest priority Voice Access Class 202. According to the Wi-Fi Multimedia Standard, the Voice Access Class queue has the smallest arbitration inter-frame interval and the smallest contention window, meaning it has the highest preemption probability when the channel is idle, thus ensuring the lowest transmission latency.

[0054] The second category is the primary data stream used for remote monitoring, specifically multiple high-definition video streams 203 transmitted from various subordinate vehicle-mounted units 102, 103, and 104. This type of data has extremely high bandwidth requirements but a relatively high tolerance for latency, and is therefore mapped to the second-highest priority video access category 204. The channel access parameters of the video access category have a lower priority than the voice access category but a higher priority than other categories, ensuring smooth video transmission.

[0055] The third category is routine vehicle status data 205, such as telemetry information like GPS coordinates, speed, and acceleration. This type of data has low requirements for bandwidth and latency, so it is mapped to the lower priority best-effort category 206.

[0056] After all data streams are mapped to their respective access class queues, they are scheduled and compete for channel access by the Media Access Control (MAC) layer 207 according to strict priorities. Simultaneously, Wi-Fi 6's Orthogonal Frequency Division Multiple Access (OFDMA) and Multiple-User Multiple-Input Multiple-Output (MPMIMO) technologies are fully utilized. OFDMA allows a channel to be divided into multiple smaller resource units in the frequency domain and allocated to different users (vehicle units), enabling the system to transmit multiple small data packets, such as control commands and status data, in parallel uplink or downlink. MPMIMO allows the simultaneous transmission of different data streams to multiple users using a multi-antenna system in space. The combination of these two technologies significantly improves spectral efficiency and concurrent transmission capabilities, allowing high-bandwidth video streams and low-latency control commands to coexist harmoniously. Ultimately, all data is modulated by the physical layer 208 and transmitted into the wireless channel.

[0057] Another key aspect of this application's embodiments lies in its built-in autonomous emergency management and safe braking logic within the subordinate vehicle unit. Please refer to [the relevant documentation / reference]. Figure 3 , Figure 5 and Figure 6After the system enters the data transmission and reception state (step S503), each subordinate vehicle unit 102, 103, and 104 will initiate a communication link quality monitoring task in parallel, i.e., step S504. This task continuously monitors the communication link status with the master vehicle unit 101, and its monitoring indicators mainly include: 1. Heartbeat signal reception: The master vehicle unit 101 is configured to broadcast an encrypted "heartbeat" signal containing a timestamp and sequence number to all subordinate vehicles at a fixed frequency (e.g., 10 Hz, i.e., once every 100 milliseconds). Figure 6 As shown, during normal communication, the master control unit (M) periodically sends heartbeat signals to the slave unit (S). The slave vehicle unit determines the viability of the physical link and network connection by checking whether it can stably and continuously receive these heartbeat signals. 2. Control command transmission delay: The slave vehicle unit records the timestamp of each received remote control command and compares it with the timestamp sent by the master control unit carried in the command to calculate the end-to-end transmission delay. 3. Control command packet loss rate: By checking whether the received control command sequence numbers are consecutive, the slave vehicle unit can calculate the packet loss rate of the commands.

[0058] After monitoring the communication link quality in step S504, the system executes step S505 to determine whether the quality is below a preset threshold. In this embodiment, two threshold levels are preset to correspond to a two-level emergency response.

[0059] Please see Figure 3 The system is in normal operating state 301 during normal operation. When the slave vehicle unit detects that the communication quality indicators meet trigger condition A 305, the system will transition from normal operating state 301 to Level 1 emergency response 302. As a specific implementation, trigger condition A 305 can be defined as: "Within a 1-second sliding time window, the calculated average end-to-end latency of the remote control command consistently exceeds 200 milliseconds, or the command packet loss rate exceeds 15%." Once Level 1 emergency response 302 is entered, the slave vehicle unit will immediately send a command to the vehicle's powertrain or vehicle stability system via its controller area network bus interface to limit the vehicle's maximum speed to a very low safe value, such as 5 km / h. Simultaneously, it will send a warning message to the master vehicle unit 101, informing the remote operator that the current communication link quality has deteriorated and the vehicle has entered restricted mode.

[0060] If the communication situation deteriorates further, or a sudden and complete communication outage occurs, the system will trigger a higher-level emergency response. When the subordinate vehicle unit detects that the communication quality indicators meet trigger condition B 306, regardless of whether it is currently in normal operation state 301 or Level 1 emergency response 302, the system will immediately switch to Level 2 emergency response 303. In this embodiment, trigger condition B 306 can be defined as: "No valid 'heartbeat' signal is received within a continuous 500-millisecond time window." Figure 6 As shown, when a heartbeat signal is lost, the slave unit's timer starts. If no new heartbeat is received within the timeout period (500 milliseconds), a safety operation is triggered.

[0061] Once the Level 2 emergency response (303) is initiated, the subordinate onboard unit will seize control of the vehicle and immediately execute a pre-set safety braking procedure. This procedure ignores any subsequent remote control commands and sends instructions to the vehicle's brake-by-wire system via the controller area network bus interface to brake at a safe and gradual deceleration (e.g., 1.5 m / s²) until the vehicle comes to a complete stop. During braking, the vehicle's hazard warning lights will automatically illuminate to alert surrounding road users. After the vehicle comes to a complete stop, the system sends a "status notification (braking)" message to the master control unit, informing them that the vehicle has stopped safely. The system then transitions to a safe standby state (304), awaiting manual intervention or communication restoration. This series of autonomous emergency management processes (step S506) forms a complete closed loop, ensuring that in any communication anomaly, the subordinate vehicle can autonomously enter a defined safe state, effectively avoiding the risk of loss of control due to communication failure.

[0062] Example 2 This embodiment aims to illustrate that the technical solution proposed in this application is flexible in its specific implementation and is not limited to a particular routing protocol. As an optional implementation, this embodiment provides a variant scheme that uses different routing protocols.

[0063] In this embodiment, the overall architecture, hardware configuration (including processor, Wi-Fi 6 module, antenna system, etc.), service quality priority scheduling mechanism based on the Wi-Fi multimedia standard, and hierarchical emergency management logic built into the subordinate vehicle units of the vehicle platooning communication and emergency management system are all the same as those described in Embodiment 1. The difference lies in that the network layer routing protocol used by the vehicle-mounted ad hoc Wi-Fi Mesh network 100 in this embodiment is replaced by the optimized on-demand open shortest path first protocol in Embodiment 1 with the hybrid wireless mesh protocol defined in the IEEE 802.11s standard.

[0064] The hybrid wireless mesh protocol combines the advantages of active routing and on-demand routing. Specifically, in the vehicle platoon of this embodiment, the master vehicle unit 101 is typically designated as the root node of the network. The protocol actively and periodically broadcasts routing announcement messages centered on this root node, thereby pre-establishing and maintaining a routing tree in the network rooted at the master vehicle unit 101, reaching all subordinate vehicle units 102, 103, and 104. The advantage of this active routing approach is that when a subordinate vehicle needs to send data to the master vehicle (e.g., transmit a high-definition video stream 203), its path to the root node is pre-calculated, eliminating the need for an ad-hoc route discovery process and reducing latency during the initial data transmission.

[0065] Meanwhile, for communication needs between non-root nodes, such as when one subordinate vehicle unit needs to communicate directly with another subordinate vehicle unit, the hybrid wireless mesh protocol will adopt an on-demand routing approach. This is similar to the on-demand open shortest path first protocol, which only initiates a routing request to find a path when needed.

[0066] During operation, when vehicles travel in a relatively stable linear formation on highways with infrequent formation changes, the active routing mechanism of the hybrid wireless mesh protocol can efficiently maintain the optimal communication path from each subordinate vehicle to the master vehicle, enabling the stable transmission of video streams and status data required for remote takeover with low latency. When the convoy needs to change formation, or in complex scenarios such as urban intersections where the relative positions of vehicles change significantly, its on-demand routing component can flexibly and quickly establish new temporary communication links between nodes.

[0067] The remaining data transmission processes, including mapping remote control commands / heartbeats 201 to voice access category 202, and the emergency response procedure for triggering autonomous safety braking in the event of communication interruption, are consistent with those described in Embodiment 1. The expected effect of this embodiment is that, in specific scenarios such as long straight road sections with fixed formations, the initial latency of data transmission may be slightly lower than that of a purely on-demand routing scheme because the routing information has been pre-established. This embodiment demonstrates that the core inventive concept of this application does not rely on a specific routing protocol. Any Mesh routing protocol capable of achieving dynamic networking and path selection, including but not limited to optimized link-state routing protocols, can be applied to the technical solution of this application, reflecting the wide applicability of the solution.

[0068] Example 3 This embodiment aims to demonstrate a more refined and progressive emergency response model. By setting more levels of response, it addresses different degrees of communication quality degradation, thereby providing a smoother system degradation experience and richer security redundancy.

[0069] In this embodiment, the system's hardware configuration, network construction method (including the formation of the Wi-Fi Mesh network 100), and data stream priority scheduling mechanism based on Wi-Fi multimedia (such as...) Figure 2 All (as shown) are consistent with Embodiment 1. The core difference in this embodiment is that the emergency management module inside the subordinate vehicle unit has been modified, and its state machine has been expanded from the two-level response model of Embodiment 1 to a three-level response model.

[0070] Specifically, when the subordinate vehicle unit performs step S504 of monitoring the communication link quality, it compares the monitored indicators with three different thresholds to trigger different levels of emergency response: 1. Level 1 Response (Warning Level): The trigger conditions for this level are set to be more sensitive, used to capture slight fluctuations in communication quality at the initial stage. For example, the trigger condition can be defined as: "Within the past 1-second sliding window, the average end-to-end latency of the remote control command first exceeds 150 milliseconds but is less than 300 milliseconds." When this condition is met, the system enters the Level 1 response state. In this state, the autonomous system of the subordinate vehicle unit does not perform any physical intervention on the vehicle's driving status, and the vehicle's behavior is unaffected. Its only action is to send a "communication quality degradation" warning message to the master vehicle unit 101. Correspondingly, a yellow warning icon or text prompt may pop up on the remote operator's interface, reminding them that the current link is unstable, but their operating permissions are not affected.

[0071] 2. Level Two Response (Intervention Level): This level has more stringent triggering conditions, indicating a significant and sustained deterioration in communication quality. For example, the triggering condition can be defined as: "The average end-to-end latency of remote control commands consistently exceeds 300 milliseconds, or the command packet loss rate consistently exceeds 20% within 2 seconds." When this condition is met, the system enters Level Two Response status. In this state, the subordinate vehicle unit will actively intervene, limiting the vehicle's maximum speed to a relatively high safe speed, such as 10 km / h, to ensure that even if command delays occur, the vehicle's dynamic changes remain within a controllable range. Simultaneously, the system will send a critical warning message to the master control unit; a prominent red warning may be displayed on the operator interface, accompanied by an audible alert, urging the operator to prepare for potential communication interruptions.

[0072] 3. Level 3 Response (Braking Level): This level represents the highest level of safety assurance. Its triggering conditions are similar to those of Level 2 Response in Example 1, indicating that the communication link has been completely interrupted or is extremely unreliable. The triggering condition can be defined as: "No valid 'heartbeat' signal is received within 500 consecutive milliseconds," or an additional redundant condition can be added, such as "Reporting via the controller area network bus, three consecutive failures or timeouts of remote control commands are detected." Once this condition is met, the system immediately enters Level 3 Response state and performs the exact same actions as Level 2 Response 303 in Example 1: immediately seizing control, ignoring all subsequent remote commands, and automatically executing a safe braking procedure with a gradual deceleration until the vehicle comes to a complete stop in safe standby state 304.

[0073] A specific work scenario can help us better understand this model. Imagine a convoy of remotely controlled vehicles is traveling when a large container truck suddenly merges into the convoy, partially obstructing the wireless signal between the master vehicle and a subordinate vehicle. Initially, the signal is only slightly interfered with; the subordinate vehicle detects a control command delay increasing from the normal 50 milliseconds to 180 milliseconds, triggering a Level 1 response. The safety operator in the lead vehicle sees a yellow warning icon on their screen. Subsequently, due to changes in the convoy's position, the obstruction becomes more severe, and the command delay spikes to 320 milliseconds. At this point, the system automatically triggers a Level 2 response, smoothly reducing the subordinate vehicle's speed to 10 km / h, and a red alert appears on the safety operator's screen. Finally, the subordinate vehicle completely enters a signal blind spot, with its heartbeat signal continuously lost for over 500 milliseconds. The system immediately triggers a Level 3 response, automatically and smoothly bringing the vehicle to a stop at the roadside and activating its hazard lights.

[0074] It is understandable that the three-level response strategy provided in this embodiment offers a more hierarchical and predictive safety guarantee compared to a two-level response. It can issue a warning only when communication quality slightly deteriorates without interfering with normal driving, avoiding unnecessary driving interruptions; it only limits vehicle capabilities when communication quality severely deteriorates, giving the operator reaction time; and it only executes the final braking operation in the most extreme case of complete communication link failure. This fully demonstrates that the "tiered emergency response" concept proposed in this application can be flexibly implemented into various specific response strategies with different levels and thresholds according to different safety needs and application scenarios.

[0075] Example 4 This embodiment aims to illustrate the core inventive concept of this application, namely, the technical solution that combines building a local self-organizing network, implementing quality of service priority scheduling, and incorporating built-in autonomous emergency management logic. Its effectiveness does not entirely depend on specific high-end hardware configurations. This embodiment demonstrates a configuration that uses a more economical and simplified hardware solution to achieve the core functions of this application, making it suitable for cost-sensitive application scenarios.

[0076] In this embodiment, the core software logic of the system includes the construction protocol of the in-vehicle self-organizing Wi-Fi Mesh network 100, and the data stream priority allocation and scheduling method based on the Wi-Fi multimedia standard (such as...). Figure 2 As shown), and a hierarchical autonomous emergency management and safety braking mechanism based on communication link status monitoring (such as...). Figure 3 , Figure 5 , Figure 6 As shown in the figure, all are consistent with those described in Embodiment 1. The main difference in this embodiment is that the hardware configuration of the vehicle-mounted unit has been simplified.

[0077] Specifically, the hardware simplification is mainly reflected in the following two aspects: 1. Simplified antenna system configuration: In this embodiment, the vehicle unit no longer uses the 4x4 multiple-input multiple-output (MIMO) and polarization diversity design described in Embodiment 1, but instead adopts a more common 2x2 MIMO configuration. For example, a standard omnidirectional antenna is installed at both the front and rear of the vehicle roof, utilizing only spatial diversity to combat signal fading, without employing polarization diversity. The antenna gain can also be a standard 3-5 dBi antenna, rather than a high-gain antenna. 2. Adjustment of communication module selection: In this embodiment, a consumer-grade Wi-Fi 6 communication module with slightly lower performance parameters and lower cost can be used to replace the industrial-grade module used in Embodiment 1. The transmit power and receive sensitivity of such consumer-grade modules may be lower than those of industrial-grade products, and their operational stability under extreme temperature and vibration environments may also differ.

[0078] The system employing the simplified hardware configuration described above retains its core workflow and logic entirely. Upon vehicle startup, it can still automatically discover and establish an encrypted Wi-Fi Mesh network 100. During data transmission, remote control commands / heartbeats 201 will still be assigned the highest priority (voice access category 202) to ensure minimal transmission latency. In terms of emergency management, the subordinate onboard unit will continue to monitor heartbeat signals and command latency, and will autonomously trigger a safety braking operation in the event of a communication interruption.

[0079] However, due to the reduced hardware performance, the system's maximum performance will be lower than that of Embodiment 1. Specifically: First, due to the decrease in antenna system gain and MIMO performance, its maximum effective communication distance will be shortened. For example, Embodiment 1 can support stable backhaul of multiple high-definition video streams over a distance of hundreds of meters, while in this embodiment, this distance may be reduced to around one hundred meters. Second, in complex environments with severe multipath effects and electromagnetic interference, the stability of the communication link may decrease due to the lack of polarization diversity and stronger signal processing capabilities, and packet loss rate and latency jitter may increase. Finally, the system's maximum network throughput will be reduced, and it may not be able to support the concurrent backhaul of four or more 1080p high-definition video streams as in Embodiment 1, or it may be necessary to reduce the video resolution or frame rate, or reduce the number of video streams to ensure transmission quality.

[0080] Despite these performance trade-offs, the system in this embodiment remains fully capable of handling tasks in many typical vehicle platooning scenarios, such as highway platooning with good visibility and close vehicle spacing (e.g., within 100 meters). It can still reliably transmit critical remote control commands, guaranteeing a low latency response of less than 50 milliseconds, and stably transmit at least 1-2 high-definition video streams, providing necessary visual information to the remote operator. Most importantly, the core safety feature of this application—the autonomous emergency braking mechanism based on communication link status—is completely unaffected by simplified hardware configurations. This is because the function is triggered by deterministic logic (such as heartbeat signal timeout), which will execute correctly as long as the basic communication capabilities exist.

[0081] The intended effect of this embodiment is to realize a fully functional vehicle platooning communication and emergency management system at a lower hardware cost. It demonstrates the universality and core value of this application: its innovation lies primarily in the ingenious combination of system architecture, software-defined quality-of-service scheduling methods, and autonomous emergency management logic, rather than simply relying on expensive hardware. This allows the technical solution to be flexibly tailored according to cost and performance requirements, possessing strong engineering and commercial value.

[0082] Those skilled in the art will understand that, besides implementing the system and its various devices, modules, and units provided by this invention in the form of purely computer-readable program code, the same functions can be achieved entirely through logical programming of the method steps, making the system and its various devices, modules, and units of this invention function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, the system and its various devices, modules, and units provided by this invention can be considered as a hardware component, and the devices, modules, and units included therein for implementing various functions can also be considered as structures within the hardware component; alternatively, the devices, modules, and units for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0083] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.

Claims

1. A vehicle platoon communication and emergency management system, applied to a vehicle platoon consisting of at least one lead vehicle and one or more subordinate vehicles, the system comprising a master control vehicle-mounted unit installed in the lead vehicle and subordinate vehicle-mounted units installed in the subordinate vehicles, characterized in that, The master control vehicle unit and the slave vehicle unit are configured to jointly construct a vehicle-mounted self-organizing Wi-Fi Mesh network; The system is configured to concurrently transmit, based on a preset priority, a first data stream for remote monitoring and a second data stream for vehicle control, wherein the transmission priority of the second data stream is higher than that of the first data stream. The subordinate vehicle unit is configured to monitor the communication link status with the master vehicle unit, and autonomously trigger a preset safety operation when the communication link status is worse than a preset threshold.

2. The system according to claim 1, characterized in that, The system is configured to comply with WMM Quality of Service standards to map the second data stream to the highest priority voice access class AC_VO for transmission.

3. The system according to claim 1, characterized in that, The master control vehicle unit is configured to periodically send heartbeat signals; the slave vehicle unit determines the communication link status by monitoring the reception of the heartbeat signals.

4. The system according to claim 1, characterized in that, The safety operation includes a tiered emergency response; The subordinate vehicle unit is configured to: execute a first-level response to limit the speed of the subordinate vehicle when the communication link status is worse than a first threshold; and execute a second-level response to decelerate the subordinate vehicle to a stop when the communication link status is worse than a second threshold.

5. The system according to claim 1, characterized in that, Both the master control vehicle unit and the slave vehicle unit are equipped with a multi-antenna system, which adopts spatial diversity and polarization diversity design.

6. A vehicle platoon communication and emergency management method, applied to a vehicle platoon consisting of at least one lead vehicle and one or more subordinate vehicles, wherein the method is executed by a master control on-board unit installed in the lead vehicle and subordinate on-board units installed in the subordinate vehicles, characterized in that, Includes the following steps: Constructing an in-vehicle self-organizing Wi-Fi Mesh network; Based on a preset priority, concurrent transmission includes a first data stream for remote monitoring and a second data stream for vehicle control, wherein the transmission priority of the second data stream is higher than that of the first data stream. The subordinate vehicle unit monitors the communication link status between itself and the master vehicle unit, and autonomously executes a preset safety operation when the communication link status is worse than a preset threshold.

7. The method according to claim 6, characterized in that, The steps of concurrently transmitting the first data stream and the second data stream include: Following the WMM Quality of Service standard, the second data stream is mapped to the highest priority voice access category AC_VO for transmission.

8. The method according to claim 6, characterized in that, The steps for monitoring the status of the communication link include: The subordinate vehicle unit receives heartbeat signals periodically sent by the master vehicle unit, and determines the communication link status based on the reception status of the heartbeat signals.

9. The method according to claim 6, characterized in that, The steps for autonomously executing preset security operations include: When the communication link status deteriorates below a first threshold, a Level 1 response is executed to limit the speed of the subordinate vehicle; and, When the communication link status is worse than the second threshold, a secondary response is executed to decelerate the subordinate vehicle to a stop.

10. The method according to claim 6, characterized in that, The steps of concurrently transmitting the first data stream and the second data stream include: Spatial diversity and polarization diversity techniques are used to transmit and receive wireless signals.

Citation Information

Patent Citations

  • Method and system for controlling multiple vehicles

    CN106898133A

  • Clustering-based mixed data distribution method in urban scene

    CN115662116A

  • Unmanned vehicle cluster control method and system based on dynamic master-slave switching

    CN119126814A

  • Multi-link redundancy guarantee method for intelligent driving vehicle in extreme scene of highway

    CN120378843A

  • Communication method, device and system for automatic driving fleet

    CN120676332A