Vehicle braking system execution state management method and device and medium

By receiving and verifying the status signals of the vehicle's braking module, calculating braking capacity indicators, and managing the activation, deactivation, or degradation of autonomous driving functions, the problem of insufficient utilization of multiple braking methods in existing technologies is solved, thereby improving the usability of autonomous driving functions and user experience.

CN121590503APending Publication Date: 2026-03-03ZHIJI AUTOMOTIVE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202610085258.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-22
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

Existing technologies fail to fully utilize the combined capabilities of multiple braking methods when dealing with vehicle braking module failures, resulting in the inability to continue using autonomous driving functions, impacting user experience, and lacking a systematic evaluation mechanism.

Method used

By receiving status signals from multiple braking modules, the system performs validity verification and fault location, calculates braking capacity indicators, determines the vehicle's braking execution status based on these indicators, and outputs corresponding strategies for activating, deactivating, or downgrading autonomous driving functions.

Benefits of technology

It enables a comprehensive assessment of the vehicle's braking capability, ensuring that the autonomous driving function does not prematurely disengage in the event of a partial module failure, thereby improving the usability of the autonomous driving function and the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121590503A_ABST
    Figure CN121590503A_ABST
Patent Text Reader

Abstract

The invention relates to a vehicle braking system execution state management method and device and a medium. The method comprises the steps that state signals from a plurality of braking modules of a vehicle are received; validity verification is carried out on the state signals, and fault positioning is carried out on the brake modules according to verification results; the braking capacity indexes of the vehicle are calculated according to the fault positioning result, wherein the braking capacity indexes comprise the complete braking capacity, the complete redundant braking capacity and the low-speed redundant braking capacity; determining a braking execution state of the vehicle according to the braking capability index, wherein the braking execution state corresponds to a standby state, a fault state or a degradation state of different levels of automatic driving functions; and outputting an activation, quit or degradation strategy of the automatic driving function of the corresponding level according to the brake execution state. According to the invention, refined activation, quit and degradation management of different levels of automatic driving functions are realized, and the usability of the automatic driving functions and the user driving experience can be improved while the driving safety is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle braking control technology, and in particular to a method, device and medium for managing the execution status of a vehicle braking system. Background Technology

[0002] With the rapid development of autonomous driving technology, vehicle autonomous driving systems are evolving towards higher levels, gradually progressing from Level 2 assisted driving to Level 3 and above. According to functional safety standards, higher-level autonomous driving systems need to meet higher safety requirements. As a core component of the vehicle's actuators, the braking system needs to be designed with redundancy to ensure fault tolerance and that a backup system can take over if the main braking system fails. Currently, vehicles with redundant braking capabilities are typically equipped with multiple braking modules, including a main braking module, an auxiliary braking module, a parking brake module, and an electric braking module. These modules together constitute the vehicle's braking system. Different levels of autonomous driving functions have different requirements for the redundancy of the braking system. For example, Level 2 functions typically do not require redundant braking capabilities, while Level 3 and above functions require complete redundant braking capabilities to meet safety requirements.

[0003] Existing technologies typically employ a simplistic strategy when handling braking module failures: directly exiting intelligent driving mode or entering a degraded state when the main or redundant braking module malfunctions. This approach fails to adequately consider the combined braking capabilities of the various braking methods equipped in the vehicle, such as the braking support provided by the parking brake and electric brake in specific scenarios. Furthermore, existing technologies lack a systematic evaluation mechanism for different combinations of braking module states, making it difficult to accurately match the activation conditions of different levels of autonomous driving functions based on the vehicle's current actual braking capability. This results in situations where, even if the vehicle still possesses some braking capability, the corresponding autonomous driving functions cannot be used, impacting the user's driving experience. Therefore, a method is needed that can comprehensively evaluate the states of multiple braking modules and manage different levels of autonomous driving functions accordingly. Summary of the Invention

[0004] In view of the shortcomings of the prior art described above, the purpose of this invention is to provide a method, device and medium for managing the execution state of a vehicle braking system. By comprehensively evaluating the fault states of multiple braking modules, the overall braking capability level of the vehicle is determined, thereby realizing refined activation, deactivation and downgrading management of different levels of autonomous driving functions. While ensuring driving safety, this invention can improve the availability of autonomous driving functions and the user driving experience.

[0005] To achieve the above objectives, the present invention adopts the following technical solution.

[0006] In a first aspect, the present invention provides a method for managing the execution state of a vehicle braking system, which adopts the following technical solution: A method for managing the execution state of a vehicle braking system, comprising: Receive status signals from multiple braking modules of the vehicle, including a main braking module, an auxiliary braking module, a parking brake module, and an electric braking module; The validity of the status signal is verified, and the fault location of each braking module is performed based on the verification result; The vehicle's braking capacity index is calculated based on the fault location results. The braking capacity index includes full braking capacity, full redundant braking capacity, and low-speed redundant braking capacity. The braking execution state of the vehicle is determined based on the braking capability index, and the braking execution state corresponds to the standby state, fault state, or degraded state of different levels of automated driving functions; and Based on the braking execution state, output the activation, deactivation, or downgrade strategy of the corresponding level of autonomous driving function.

[0007] Furthermore, in the above method, the parking brake module includes a main parking brake module and an auxiliary parking brake module.

[0008] Furthermore, in the above method, the low-speed redundant braking capability is determined by the availability of the electric braking module and the availability of at least one of the main parking brake module or the auxiliary parking brake module.

[0009] Furthermore, in the above method, the low-speed redundant braking capability is also constrained by a vehicle speed threshold. When the vehicle speed is not higher than the vehicle speed threshold, the parking brake module will not cause the vehicle to become unstable when it participates in braking.

[0010] Furthermore, in the above method, the complete braking capacity is determined by the availability of the main braking module or the availability of the auxiliary braking module, and the complete redundant braking capacity is determined by the availability of both the main braking module and the auxiliary braking module.

[0011] Furthermore, in the above method, the braking execution state includes: The OFF state indicates that the vehicle does not have braking capability; L2 standby state indicates that the vehicle has full braking capability but no redundancy requirement. L2 fault status indicates that both the main braking module and the auxiliary braking module have failed. L3 standby status indicates that the vehicle has full braking capability and full redundant braking capability; L3 downgraded driving status indicates that the vehicle's main and auxiliary braking capabilities have a single fault but it has low-speed redundant braking capability. L3 safe parking status indicates that both the main and auxiliary braking capabilities of the vehicle are faulty or the low-speed redundant braking capability is also faulty. L4 parking standby mode indicates that the vehicle has full braking capability and low-speed redundant braking capability; and L4 parking fault status indicates that the vehicle does not have full braking capability or no low-speed redundant braking capability.

[0012] Furthermore, in the above method, when the braking execution state jumps from L3 standby state to L3 degraded driving state, the method further includes executing a degraded driving strategy, which includes limiting the target vehicle speed and acceleration and prompting the driver to take over.

[0013] Furthermore, in the above method, the validity verification of the state signal includes: Perform timeout monitoring on critical messages; Perform rolling counter consistency check; and Perform a CRC check.

[0014] Furthermore, in the above method, fault location for each braking module includes: Set the entry fault confirmation time and recovery confirmation time; If a communication timeout or verification failure persists beyond the specified fault confirmation time, the corresponding module will be deemed unavailable; and When the anomaly disappears and the system continues to function normally for more than the recovery confirmation time, the corresponding module will be restored to usability.

[0015] Furthermore, in the above method, the method is executed by a software module deployed in two intelligent driving domain controllers. The two intelligent driving domain controllers periodically exchange capability indicators, state machine states, and fault summaries for consistency verification. When inconsistency is found, the system enters a more conservative state or triggers an exit or safe parking strategy.

[0016] Secondly, the present invention provides a vehicle braking system execution state management device, which adopts the following technical solution: A vehicle braking system execution state management device, comprising: The signal receiving module is configured to receive status signals from multiple braking modules of the vehicle, including a main braking module, an auxiliary braking module, a parking brake module, and an electric braking module. The verification module is configured to verify the validity of the status signal and locate the fault in each braking module based on the verification result. The capability calculation module is configured to calculate the vehicle's braking capability index based on the fault location result. The braking capability index includes full braking capability, full redundant braking capability, and low-speed redundant braking capability. A state determination module is configured to determine the braking execution state of the vehicle based on the braking capability index, wherein the braking execution state corresponds to a standby state, a fault state, or a degraded state for different levels of automated driving functions; and The strategy output module is configured to output activation, deactivation, or downgrade strategies for the corresponding level of autonomous driving function based on the braking execution state.

[0017] Thirdly, the present invention provides a readable storage medium, which adopts the following technical solution: A readable storage medium storing computer instructions that, when executed by a processor, implement the vehicle braking system execution state management method as described in any one of the first aspects above.

[0018] In summary, compared with the prior art, the present invention has at least one of the following beneficial technical effects: This invention, by receiving status signals from multiple braking modules and performing validity verification and fault location, enables a comprehensive assessment of a vehicle's braking capability. It determines the vehicle's braking execution state based on multi-dimensional indicators such as complete braking capability, complete redundant braking capability, and low-speed redundant braking capability. This method can correlate the braking execution state with the standby, fault, or degraded states of different levels of autonomous driving functions, thereby outputting corresponding activation, deactivation, or degrade strategies. This invention fully utilizes the combined capabilities of the various braking modules equipped in the vehicle, avoiding premature deactivation of autonomous driving functions when some braking modules fail, thus improving the availability of autonomous driving functions while ensuring driving safety. In some cases, this method can also achieve more refined function management based on the differentiated requirements of different levels of autonomous driving functions for braking redundancy capabilities, improving the user's driving experience. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A flowchart of a vehicle braking system execution state management method according to an embodiment of the present invention is shown.

[0021] Figure 2 A flowchart of the low-speed redundant braking capability determination method in an embodiment of the present invention is shown.

[0022] Figure 3A flowchart illustrating the validity verification and fault location of the braking module status signal in an embodiment of the present invention is shown.

[0023] Figure 4 A flowchart of consistency verification for dual intelligent driving domain controllers in an embodiment of the present invention is shown.

[0024] Figure 5 A module structure diagram of the vehicle braking system execution state management device in an embodiment of the present invention is shown. Detailed Implementation

[0025] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Furthermore, it should be understood that the specific embodiments described herein are only for illustration and explanation of this application and are not intended to limit this application.

[0026] It should be noted that the order of description of the following embodiments is not intended to limit the preferred order of the embodiments of this application. Furthermore, the descriptions of each embodiment in the following embodiments have their own emphasis; for parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0027] The method steps described in this embodiment of the invention can be executed in the order described in the specific implementation, or the execution order of each step can be adjusted according to actual needs, provided that the technical problem can be solved. These are not listed one by one here.

[0028] The present invention will be further described in detail below with reference to the accompanying drawings.

[0029] Reference Figure 1 , Figure 1 A flowchart of a vehicle braking system execution state management method is shown. This method is used to manage the activation, deactivation, or degradation of autonomous driving functions based on the states of multiple braking modules in the vehicle.

[0030] In step 100, status signals from multiple braking modules of the vehicle are received. These multiple braking modules include a main braking module, an auxiliary braking module, a parking brake module, and an electric braking module. The main braking module provides braking capability for the vehicle in primary scenarios. The auxiliary braking module provides backup braking capability for the vehicle when the main braking module fails. The parking brake module provides braking force when the vehicle is parked and can provide braking capability to bring the vehicle to a stop in emergency situations. The electric braking module uses an energy recovery motor to provide braking capability to the vehicle by reverse dragging.

[0031] Continue to refer to Figure 1 In step 102, the status signals are validated, and fault location is performed on each braking module based on the validation results. Validity validation is used to determine whether the status signals sent by each braking module are valid, and fault location is used to determine the availability status of each braking module.

[0032] In step 104, fault location is performed on each braking module based on the verification results. Fault location integrates communication anomaly flags, diagnostic fault information, and module self-test status to generate a unified availability output for each braking module.

[0033] like Figure 1 As shown, in step 106, the vehicle's braking capability index is calculated based on the fault location results. The braking capability index includes full braking capability, full redundant braking capability, and low-speed redundant braking capability. Full braking capability characterizes whether the vehicle possesses basic service braking capability. Full redundant braking capability characterizes whether it meets the redundant braking requirements of higher-level automated driving. Low-speed redundant braking capability characterizes whether it possesses redundant braking capability in low-speed scenarios.

[0034] In step 108, the vehicle's braking execution state is determined based on braking capacity indicators. The braking execution state corresponds to the standby state, fault state, or degraded state of different levels of automated driving functions. Different levels of automated driving functions include L2 automated driving, L3 automated driving, and L4 automated parking.

[0035] Continue to refer to Figure 1 In step 110, the activation, deactivation, or degrading strategy for the corresponding level of automated driving function is output based on the braking execution state. When the braking execution state meets the activation conditions for the corresponding level of automated driving function, an activation strategy is output. When the braking execution state does not meet the operating conditions for the corresponding level of automated driving function, a deactivation or degrading strategy is output.

[0036] In some implementations, the vehicle network uses a CAN bus for communication between the intelligent driving domain controller and each braking module. In some implementations, the vehicle network uses a CAN-FD bus for communication between the intelligent driving domain controller and each braking module. In some implementations, the vehicle network uses other onboard buses for communication between the intelligent driving domain controller and each braking module.

[0037] In some implementations, the intelligent driving domain controller exchanges vehicle speed information, gear information, gradient information, and driver takeover request information with other domains of the vehicle through a gateway. This information is used to assist in determining the activation conditions and degrade thresholds for different levels of autonomous driving.

[0038] Reference Figure 2 , Figure 2 A flowchart of a low-speed redundant braking capability determination method 200 is shown. The low-speed redundant braking capability determination method 200 is used to determine whether a vehicle has redundant braking capability in low-speed scenarios. The parking brake module includes a main parking brake module and an auxiliary parking brake module. The main parking brake module provides braking force when the vehicle is parked and can provide braking capability to stop the vehicle in an emergency. The auxiliary parking brake module provides parking braking capability to the vehicle when the main parking brake module fails.

[0039] In step 202, it is determined whether the electric braking module is available. The electric braking module uses an energy recovery motor to provide braking capability to the vehicle by dragging it in the opposite direction. If the electric braking module is unavailable, the low-speed redundant braking capability determination method 200 proceeds to step 208, determining that the vehicle does not have low-speed redundant braking capability.

[0040] Continue to refer to Figure 2 If the electric braking module is available, the low-speed redundant braking capability determination method 200 proceeds to step 204 to determine whether at least one of the main parking brake module or the auxiliary parking brake module is available. If neither the main parking brake module nor the auxiliary parking brake module is available, the low-speed redundant braking capability determination method 200 proceeds to step 210 to determine that the vehicle does not have low-speed redundant braking capability.

[0041] like Figure 2 As shown, if at least one of the main parking brake module or the auxiliary parking brake module is available, the low-speed redundant braking capability determination method 200 proceeds to step 206 to determine whether the vehicle speed is not higher than a vehicle speed threshold. In some embodiments, the vehicle speed threshold is set to 20 km / h. If the vehicle speed is not higher than the vehicle speed threshold, the low-speed redundant braking capability determination method 200 proceeds to step 212 to determine that the vehicle has low-speed redundant braking capability. If the vehicle speed is higher than the vehicle speed threshold, the low-speed redundant braking capability determination method 200 proceeds to step 214 to determine that the vehicle does not have low-speed redundant braking capability.

[0042] Continue to refer to Figure 2 Low-speed redundant braking capability is determined by the availability of the electric braking module and the availability of at least one of the main parking brake module or the auxiliary parking brake module. Low-speed redundant braking capability is also constrained by a vehicle speed threshold; when the vehicle speed is not higher than the threshold, the parking brake module's braking will not cause vehicle instability. Using the parking brake module in scenarios with vehicle speeds greater than 20 km / h poses a risk of vehicle instability.

[0043] The combination of the electric braking module and the parking brake module decelerates the vehicle and brings it to a safe stop. The electric braking module cannot bring the vehicle to a complete stop; it achieves deceleration by generating reverse torque to resist wheel rotation. However, the braking force generated by the electric braking module decreases as the vehicle speed drops below a certain level. The parking brake module engages braking once the vehicle speed falls below a certain threshold, bringing the vehicle to a safe stop. Through the combination of the electric braking module and the parking brake module, the vehicle possesses redundant braking capabilities in low-speed scenarios.

[0044] Full braking capability is determined by the availability of either the main braking module or the auxiliary braking module. When the main braking module is available, the vehicle has full braking capability. When the auxiliary braking module is available, the vehicle has full braking capability. When neither the main braking module nor the auxiliary braking module is available, the vehicle does not have full braking capability.

[0045] Full redundancy braking capability is determined by the availability of both the main braking module and the auxiliary braking module. When both the main and auxiliary braking modules are available, the vehicle possesses full redundancy braking capability. When either the main or auxiliary braking module is unavailable, the vehicle does not possess full redundancy braking capability. Full redundancy braking capability is used to meet the redundancy braking requirements of higher levels of automated driving.

[0046] Braking operation states include OFF state, L2 standby state, L2 fault state, L3 standby state, L3 degraded driving state, L3 safe stop state, L4 parking standby state, and L4 parking fault state. OFF state indicates that the vehicle lacks braking capability. The vehicle enters the OFF state when both the main braking module and the auxiliary braking module are unavailable.

[0047] L2 standby state indicates that the vehicle has full braking capability but no redundancy requirement. L2 autonomous driving function does not require redundant braking capability; it is allowed to activate when the vehicle has full braking capability. L2 fault state indicates that both the main braking module and the auxiliary braking module have failed. When the vehicle is in an L2 fault state, it does not have full braking capability.

[0048] Level 3 standby mode indicates that the vehicle possesses full braking capability and full redundancy braking capability. The vehicle enters Level 3 standby mode when both the main braking module and the auxiliary braking module are available. Level 3 autonomous driving functions are allowed to be activated in Level 3 standby mode.

[0049] Level 3 (L3) degraded driving state indicates that the vehicle's main and auxiliary braking capabilities are both faulty, but it still possesses low-speed redundant braking capability. When either the main or auxiliary braking module fails, but the electric braking module is available, and at least one of the main or auxiliary parking brake modules is available, the vehicle enters L3 degraded driving state. In L3 degraded driving state, the vehicle slows down so that if the braking fails again, a combination of the parking brake module and the electric braking module can bring the vehicle to a stop.

[0050] Level 3 safe stop status indicates that both the main and auxiliary braking capabilities of the vehicle are faulty, or that the low-speed redundant braking capability is also faulty. The vehicle enters Level 3 safe stop status when both the main and auxiliary braking modules are faulty. The vehicle enters Level 3 safe stop status when only one of the main or auxiliary braking capabilities is faulty, and the low-speed redundant braking capability is also faulty.

[0051] Level 4 parking standby mode indicates that the vehicle possesses full braking capability and low-speed redundant braking capability. Level 4 automated parking function is allowed to be activated in Level 4 parking standby mode. Level 4 parking fault mode indicates that the vehicle lacks full braking capability or low-speed redundant braking capability. When the vehicle is in Level 4 parking fault mode, Level 4 automated parking function is not allowed to be activated.

[0052] When the braking execution state transitions from L3 standby to L3 degraded driving state, a degraded driving strategy is implemented. This strategy includes limiting the target vehicle speed and acceleration, and prompting the driver to take over. During the execution of the degraded driving strategy, the autonomous driving module continuously monitors whether redundant braking capability can be restored. When redundant braking capability is restored, the braking execution state transitions back from L3 degraded driving state to L3 standby state.

[0053] When the braking execution state transitions to L3 safe stop or OFF state, the autonomous driving module triggers the minimum risk strategy. The minimum risk strategy includes executing a safe stop and prohibiting reactivation until the recovery conditions are met. The recovery conditions include the elimination of the braking module fault and the braking capability indicators meeting the activation conditions for the corresponding level of autonomous driving function.

[0054] In some implementations, the state machine module sets a minimum dwell time and transition debouncing logic to avoid boundary jitter. The minimum dwell time ensures that the braking execution state remains for a period of time after the transition, avoiding frequent state transitions due to transient signal changes. The transition debouncing logic filters the state transition conditions to prevent erroneous state transitions caused by signal glitches.

[0055] In some implementations, the state machine module specifies transition priorities. The OFF state and the L3 safe stop state have higher priority than other states. When multiple triggering conditions are met simultaneously, the state machine module prioritizes entering the safer state. By specifying transition priorities, it ensures that the vehicle enters a safe state when multiple braking capabilities fail.

[0056] Reference Figure 3 , Figure 3 A flowchart illustrating the validity verification and fault location of braking module status signals is provided. This flowchart is used to verify the validity of the status signals of each braking module and to locate faults in each braking module based on the verification results.

[0057] In step 300, braking module status signals are received. The signal receiving module periodically receives status signals from the main braking module, auxiliary braking module, main parking brake module, auxiliary parking brake module, and electric braking module, and performs message parsing and timestamp recording. The signal receiving module establishes a signal list for each braking-related ECU, which includes module operating mode, actuator availability, key fault codes / diagnostic status, request-response handshake status, and the upper limit of braking force / deceleration that the electric braking can provide.

[0058] Continue to refer to Figure 3 The signal receiving module performs range checks on key enumerated quantities and upper / lower limit checks on physical quantities to improve anti-interference capabilities. For transient glitches, the signal receiving module employs short-time-window filtering or majority voting to avoid erroneous state machine transitions. Range checks determine whether the enumerated quantities are within a preset valid value range. Upper / lower limit checks determine whether the physical quantities are within a preset valid value range.

[0059] like Figure 3 As shown, in step 302, timeout monitoring is performed on critical messages. Timeout monitoring is used to detect whether the status signals sent by each braking module arrive within a preset time. When a status signal does not arrive within the preset time, timeout monitoring marks the corresponding signal as invalid and outputs a communication abnormality flag.

[0060] In step 304, a rolling counter consistency check is performed. The rolling counter consistency check is used to detect the continuity and integrity of the status signal. When the value of the rolling counter is inconsistent with the expected value, the rolling counter consistency check marks the corresponding signal as invalid and outputs a communication error flag.

[0061] Continue to refer to Figure 3 In step 306, a CRC check is performed. The CRC check is used to detect whether a data error has occurred during the transmission of the status signal. When the CRC check fails, it marks the corresponding signal as invalid and outputs a communication error flag.

[0062] In step 308, it is determined whether the communication timeout or verification failure has persisted beyond the fault confirmation time. The fault location module sets the entry fault confirmation time and the recovery confirmation time. The entry fault confirmation time is used to determine how long the communication anomaly lasts before the corresponding module is deemed unavailable. The recovery confirmation time is used to determine how long after the anomaly disappears and normal operation resumes before the corresponding module is restored to availability.

[0063] like Figure 3 As shown, if the communication timeout or verification failure continues beyond the fault confirmation time, the process proceeds to step 310, where the corresponding module is determined to be unavailable. If the communication timeout or verification failure does not continue beyond the fault confirmation time, the process proceeds to step 312, where it is determined whether the disappearance of the anomaly has continued normally beyond the recovery confirmation time.

[0064] Continue to refer to Figure 3 In step 312, if the abnormality disappears and the normal operation continues for longer than the recovery confirmation time, the process proceeds to step 314 to restore the corresponding module to usability. If the abnormality disappears but the normal operation does not continue for longer than the recovery confirmation time, the process proceeds to step 316 to maintain the current module state.

[0065] The fault location module outputs a unified status variable for each braking capability unit. This unified status variable includes Avail, DegradeLevel, CommHealth, and DiagFault. Avail indicates the availability or unavailability of the braking capability unit. DegradeLevel indicates the degradation level of the braking capability unit. CommHealth indicates the communication health status of the braking capability unit. DiagFault indicates the diagnostic fault status of the braking capability unit.

[0066] In some implementations, the fault location module employs a latching strategy for critical faults affecting autonomous driving safety. The latching strategy locks the critical fault state and clears it only after preset release conditions are met. These preset release conditions include the elimination of the fault cause and system self-test confirmation. The latching strategy ensures that critical faults are not mistakenly cleared due to transient signal recovery.

[0067] Reference Figure 4 , Figure 4 A flowchart illustrating the consistency verification process for the dual intelligent driving domain controllers is shown. This vehicle braking system execution state management method is executed by software modules deployed within the two intelligent driving domain controllers. The two intelligent driving domain controllers form a redundant software execution channel to improve the reliability of braking execution state management.

[0068] In step 400, the two intelligent driving domain controllers independently perform state management. The software modules within each intelligent driving domain controller independently receive state signals from each braking module, independently perform validity verification and fault location, independently calculate braking capacity indicators, and independently determine the braking execution state.

[0069] Continue to refer to Figure 4 In step 402, the two intelligent driving domain controllers periodically exchange capability metrics, state machine states, and fault summaries for consistency verification. Capability metrics include full braking capability, full redundant braking capability, and low-speed redundant braking capability. State machine states include the current braking execution state and state transition history. Fault summaries include the availability status and fault type of each braking module. The two intelligent driving domain controllers also periodically exchange heartbeat signals, which are used to detect when the other end loses connection or experiences health abnormalities.

[0070] like Figure 4 As shown, in step 404, it is determined whether the results of the two intelligent driving domain controllers are consistent. The consistency check includes comparing whether the capability indicators calculated by the two intelligent driving domain controllers are the same, comparing whether the state machine states determined by the two intelligent driving domain controllers are the same, and comparing whether the fault summaries output by the two intelligent driving domain controllers are the same.

[0071] Continue to refer to Figure 4 If the results from the two intelligent driving domain controllers are consistent, the process proceeds to step 406, where the autonomous driving strategy is output under normal conditions. Under normal conditions, the autonomous driving strategy determines the activation, deactivation, or downgrading of the corresponding level of autonomous driving function based on the braking execution status.

[0072] If the results from the two intelligent driving domain controllers are inconsistent, the process proceeds to step 408, where the system enters a more conservative state or triggers an exit or safe parking strategy. When an inconsistency is detected, the system selects the more conservative state from the outputs of the two intelligent driving domain controllers as the current braking execution state, or directly triggers an exit or safe parking strategy to ensure vehicle safety.

[0073] In some implementations, the two autonomous driving domain controllers work in a primary / backup mode. In this mode, the primary domain controller outputs the strategy, while the backup domain controller monitors and takes over. The primary domain controller is responsible for calculating braking capability indicators, determining the braking execution status, and outputting the autonomous driving strategy. The backup domain controller synchronously executes the same calculation process and monitors the output of the primary domain controller. When the primary domain controller malfunctions or its output is inconsistent with the backup domain controller's calculation results, the backup domain controller takes over and outputs the strategy.

[0074] In some implementations, the two autonomous driving domain controllers collaborate using a dual-active voting method. In this method, the two controllers independently calculate their states and perform consistency checks. Both controllers possess full state management capabilities, and their outputs determine the final autonomous driving strategy through a voting mechanism. When the outputs of the two controllers are consistent, this consistent output is adopted as the final strategy. When their outputs are inconsistent, the more conservative output is adopted as the final strategy.

[0075] When a peer is detected to be disconnected, have an abnormal health status, or fail a consistency check, the system determines that redundancy capability is compromised and restricts the autonomous driving function according to preset rules. Peer disconnection is detected by a timeout in the heartbeat signal. Peer health abnormalities are detected by health status information carried in the heartbeat signal. When redundancy capability is compromised, the system restricts the activation of high-level autonomous driving functions or downgrades the currently running high-level autonomous driving function to a lower-level autonomous driving function.

[0076] In some implementations, key states, fault causes, jump triggering conditions, and policy execution results are recorded in a log. The log is used to trace state changes and policy execution during the braking execution state management process. The log content includes the jump time of the braking execution state, the state before the jump, the state after the jump, the conditions triggering the jump, the output autonomous driving policy, and the policy execution result.

[0077] In some implementations, logs are reported to the vehicle diagnostics and data platform on demand. The vehicle diagnostics and data platform collects and analyzes vehicle operating data. By analyzing log data, the platform traces the causes of faults, optimizes state transition thresholds, and improves degradation strategies.

[0078] This invention also discloses a vehicle braking system execution status management device.

[0079] Reference Figure 5 , Figure 5 A modular structure diagram of a vehicle braking system execution state management device 500 is shown. The vehicle braking system execution state management device 500 is used to manage the activation, deactivation, or degradation of autonomous driving functions based on the states of multiple braking modules in the vehicle. The vehicle braking system execution state management device 500 includes a signal receiving module 502, a verification module 504, a capability calculation module 506, a state determination module 508, and a strategy output module 510.

[0080] Continue to refer to Figure 5 The signal receiving module 502 is configured to receive status signals from multiple braking modules of the vehicle. These braking modules include a main braking module, an auxiliary braking module, a parking brake module, and an electric braking module. The main braking module provides braking capability for the vehicle in primary scenarios. The auxiliary braking module provides backup braking capability when the main braking module fails. The parking brake module provides braking force when the vehicle is parked and can provide braking capability to bring the vehicle to a stop in emergency situations. The electric braking module uses an energy-recovery motor to provide braking capability by reverse dragging. The signal receiving module 502 periodically receives status signals from each braking module and performs message parsing and timestamp recording.

[0081] like Figure 5As shown, the verification module 504 is connected to the signal receiving module 502. The verification module 504 is configured to verify the validity of status signals and locate faults in each braking module based on the verification results. Validity verification includes timeout monitoring of key messages, consistency verification of rolling counters, and CRC verification. The verification module 504 integrates communication anomaly flags, diagnostic fault information, and module self-test status to generate a unified availability output for each braking module. The verification module 504 sets an entry fault confirmation time and a recovery confirmation time. When communication timeout or verification failure continues beyond the entry fault confirmation time, the corresponding module is determined to be unavailable. When the anomaly disappears and normal operation continues beyond the recovery confirmation time, the corresponding module is restored to availability.

[0082] Continue to refer to Figure 5 The capability calculation module 506 is connected to the verification module 504. The capability calculation module 506 is configured to calculate the vehicle's braking capability index based on the fault location results. The braking capability index includes full braking capability, full redundant braking capability, and low-speed redundant braking capability. Full braking capability is determined by the availability of either the main braking module or the auxiliary braking module. Full redundant braking capability is determined by the availability of both the main braking module and the auxiliary braking module. Low-speed redundant braking capability is determined by the availability of the electric braking module and at least one of the main parking brake module or the auxiliary parking brake module, plus a vehicle speed threshold constraint.

[0083] like Figure 5 As shown, the state determination module 508 is connected to the capability calculation module 506. The state determination module 508 is configured to determine the vehicle's braking execution state based on braking capability indicators. The braking execution state corresponds to the standby state, fault state, or degraded state of different levels of automated driving functions. The braking execution states include OFF state, L2 standby state, L2 fault state, L3 standby state, L3 degraded driving state, L3 safe parking state, L4 parking standby state, and L4 parking fault state. The state determination module 508 determines the braking execution state based on a combination of complete braking capability, complete redundant braking capability, and low-speed redundant braking capability, and completes state updates according to jump conditions.

[0084] Continue to refer to Figure 5The strategy output module 510 is connected to the state determination module 508. The strategy output module 510 is configured to output activation, deactivation, or degrading strategies for the corresponding level of automated driving function based on the braking execution state. When the braking execution state meets the activation conditions for the corresponding level of automated driving function, the strategy output module 510 outputs an activation strategy. When the braking execution state does not meet the operating conditions for the corresponding level of automated driving function, the strategy output module 510 outputs a deactivation or degrading strategy. When the braking execution state transitions from L3 standby state to L3 degraded driving state, the strategy output module 510 outputs a degraded driving strategy, which includes limiting the target vehicle speed and acceleration, and prompting the driver to take over. When the braking execution state transitions to L3 safe stop state or OFF state, the strategy output module 510 triggers a minimum risk strategy, executes a safe stop, and prohibits reactivation until the recovery conditions are met.

[0085] like Figure 5 As shown, a data flow relationship is formed between the modules within the vehicle braking system execution state management device 500. Data flows sequentially from the signal receiving module 502 through the verification module 504, the capability calculation module 506, and the state determination module 508, finally reaching the strategy output module 510. The signal receiving module 502 transmits the received state signal to the verification module 504. The verification module 504 transmits the fault location result to the capability calculation module 506. The capability calculation module 506 transmits the braking capability index to the state determination module 508. The state determination module 508 transmits the braking execution state to the strategy output module 510. The strategy output module 510 outputs activation, deactivation, or degrading strategies for the automatic driving function based on the braking execution state.

[0086] This invention also discloses a readable storage medium.

[0087] A computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the vehicle braking system execution state management method described in any of the above embodiments. The computer-readable storage medium may include any entity or device capable of carrying a computer program, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), and a software distribution medium, etc. The computer program includes computer program code. The computer program code may be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer-readable storage medium may include any entity or device capable of carrying computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), and a software distribution medium, etc.

[0088] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.

[0089] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus or device (such as a computer-based system, a system including a processing module or other system that can fetch and execute instructions from, an instruction execution system, apparatus or device).

[0090] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for managing the execution state of a vehicle braking system, characterized in that, include: Receive status signals from multiple braking modules of the vehicle, including a main braking module, an auxiliary braking module, a parking brake module, and an electric braking module; The validity of the status signal is verified, and the fault location of each braking module is performed based on the verification result; The vehicle's braking capacity index is calculated based on the fault location results. The braking capacity index includes full braking capacity, full redundant braking capacity, and low-speed redundant braking capacity. The braking execution state of the vehicle is determined based on the braking capability index, and the braking execution state corresponds to the standby state, fault state, or degraded state of different levels of automated driving functions; and Based on the braking execution state, output the activation, deactivation, or downgrade strategy of the corresponding level of autonomous driving function.

2. The method according to claim 1, characterized in that, The parking brake module includes a main parking brake module and an auxiliary parking brake module.

3. The method according to claim 2, characterized in that, The low-speed redundant braking capability is determined by the availability of the electric braking module and the availability of at least one of the main parking brake module or the auxiliary parking brake module.

4. The method according to claim 3, characterized in that, The low-speed redundant braking capability is also constrained by a vehicle speed threshold. When the vehicle speed is not higher than the vehicle speed threshold, the parking brake module will not cause the vehicle to become unstable when it participates in braking.

5. The method according to claim 1, characterized in that, The complete braking capacity is determined by the availability of the main braking module or the availability of the auxiliary braking module, and the complete redundant braking capacity is determined by the availability of both the main braking module and the auxiliary braking module.

6. The method according to claim 1, characterized in that, The braking execution state includes: The OFF state indicates that the vehicle does not have braking capability; L2 standby state indicates that the vehicle has full braking capability but no redundancy requirement. L2 fault status indicates that both the main braking module and the auxiliary braking module have failed. L3 standby status indicates that the vehicle has full braking capability and full redundant braking capability; L3 downgraded driving status indicates that the vehicle's main and auxiliary braking capabilities have a single fault but it has low-speed redundant braking capability. L3 safe parking status indicates that both the main and auxiliary braking capabilities of the vehicle are faulty or the low-speed redundant braking capability is also faulty. L4 parking standby mode indicates that the vehicle has full braking capability and low-speed redundant braking capability; and L4 parking fault status indicates that the vehicle does not have full braking capability or no low-speed redundant braking capability.

7. The method according to claim 6, characterized in that, When the braking execution state transitions from L3 standby state to L3 degraded driving state, the method further includes executing a degraded driving strategy, which includes limiting the target vehicle speed and acceleration and prompting the driver to take over.

8. The method according to claim 1, characterized in that, Validating the status signal includes: Perform timeout monitoring on critical messages; Perform rolling counter consistency check; and Perform a CRC check.

9. The method according to claim 1, characterized in that, Fault location for each braking module includes: Set the entry fault confirmation time and recovery confirmation time; If a communication timeout or verification failure persists beyond the specified fault confirmation time, the corresponding module will be deemed unavailable; and When the anomaly disappears and the system continues to function normally for more than the recovery confirmation time, the corresponding module will be restored to usability.

10. The method according to claim 1, characterized in that, The method is executed by software modules deployed in two intelligent driving domain controllers. The two intelligent driving domain controllers periodically exchange capability indicators, state machine states, and fault summaries for consistency verification. When inconsistencies are found, the system enters a more conservative state or triggers an exit or safe parking strategy.

11. A vehicle braking system execution state management device, characterized in that, include: The signal receiving module is configured to receive status signals from multiple braking modules of the vehicle, including a main braking module, an auxiliary braking module, a parking brake module, and an electric braking module. The verification module is configured to verify the validity of the status signal and locate the fault in each braking module based on the verification result. The capability calculation module is configured to calculate the vehicle's braking capability index based on the fault location result. The braking capability index includes full braking capability, full redundant braking capability, and low-speed redundant braking capability. A state determination module is configured to determine the braking execution state of the vehicle based on the braking capability index, wherein the braking execution state corresponds to a standby state, a fault state, or a degraded state for different levels of automated driving functions; and The strategy output module is configured to output activation, deactivation, or downgrade strategies for the corresponding level of autonomous driving function based on the braking execution state.

12. A readable storage medium, characterized in that, The readable storage medium stores computer instructions that, when executed by a processor, implement the vehicle braking system execution state management method as described in any one of claims 1-10.

Citation Information

Patent Citations

  • Automatic driving transverse auxiliary control method and transverse auxiliary system

    CN112298208A

  • Fault diagnosis method, automatic driving domain controller and vehicle

    CN114194212A

  • Redundancy control system and method for autonomous vehicle and vehicle

    CN115805964A

  • Redundant braking control method and device and computer readable storage medium

    CN120308070A

  • Automatic driving control device

    JP2017157067A