Vehicle travel control method, system, and vehicle

By introducing an intelligent agent collaboration layer into the vehicle to conduct verification and evaluation processing of negotiation sessions with external intelligent agents, the problems of infeasibility, insecurity, and large latency in vehicle driving control in the prior art are solved, and safer and more accurate multi-agent collaborative control is achieved.

CN121697654BActive Publication Date: 2026-04-24NULLMAX INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NULLMAX INC
Filing Date
2026-02-12
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing vehicle driving control methods rely on centralized or semi-centralized collaborative strategies, which leads to problems such as infeasibility of vehicle control, control risks, control insecurity, and control latency. In particular, it is difficult to achieve globally optimal decision-making in multi-agent collaborative scenarios.

Method used

The vehicle's intelligent agent collaboration layer establishes a negotiation session with external intelligent agents, performs verification and evaluation processing, generates a negotiation session structure, and sends it to the task strategy layer to generate target driving control strategy instruction information under the premise of meeting safety constraints and feasibility requirements. The decentralized A2A communication protocol is used for negotiation communication.

Benefits of technology

It improves the safety, feasibility, and accuracy of vehicle driving control, reduces communication latency, and ensures the stability and real-time performance of vehicle driving control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121697654B_ABST
    Figure CN121697654B_ABST
Patent Text Reader

Abstract

The application provides a vehicle driving control method, a system and a vehicle. The system comprises an intelligent agent coordination layer and a task strategy layer arranged in the vehicle. The intelligent agent coordination layer establishes a negotiation session with at least one external intelligent agent when it is determined that the task strategy layer needs to introduce external intelligent agent capability, carries out verification and evaluation processing on the negotiation session, generates a negotiation session structure body when the verification and evaluation pass, and sends the negotiation session structure body to the task strategy layer. The task strategy layer generates target driving control strategy instruction information according to the negotiation session structure body and pre-generated driving control strategy instruction information for guiding vehicle driving when it is determined that the negotiation session structure body meets safety constraints and feasibility requirements, which is used for vehicle driving control. In this way, only the negotiation session structure body meeting the safety constraints and the feasibility requirements is adopted for vehicle driving control, thereby improving the feasibility, functionality, safety and accuracy of vehicle driving control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle control technology, and in particular to a vehicle driving control method, system and vehicle. Background Technology

[0002] With the deep integration of the automotive industry and artificial intelligence technology, vehicles have gradually evolved from the stage of assisted driving to advanced intelligent driving. In intelligent driving scenarios, multi-agent collaborative driving (such as vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-network (V2N)) has become a core direction for breaking through bottlenecks and improving traffic efficiency and safety in complex scenarios. Advanced intelligent driving needs to address scenarios such as: narrow road meeting where multiple vehicles are traveling in opposite directions and need to negotiate the order of yielding; underground parking scenarios where multiple vehicles simultaneously seek parking spaces and negotiate parking routes and allocation; unsignaled intersection scenarios where multiple vehicles negotiate the order of passage based on communication intentions; adversarial scenarios where multiple vehicles compete for and coordinate the allocation of limited resources such as roads, parking, or charging; and cross-scenario collaborative control scenarios where vehicles negotiate and interact with external intelligent entities such as charging piles, parking equipment, and smart home systems. Examples include battery preheating and power negotiation before charging, automatic parking scheduling after charging, efficient allocation of vacant parking spaces, and linkage between vehicle and home environment status before travel. In these scenarios, mutual recognition of intentions, behavior negotiation, and risk management between intelligent entities cannot achieve global optimization by relying solely on single-vehicle perception and decision-making.

[0003] Existing vehicle control decision-making methods often employ a "forced injection of external communication commands" model. This centralized or semi-centralized approach involves a centralized node or roadside unit acting as the external negotiation agent, directly generating collaborative strategies and sending them as external communication command messages to the vehicle, thus directly interfering with the vehicle's control decision generation. On one hand, the collaborative strategies generated by external agents may be incompatible with the vehicle's perceived real-time environment, vehicle dynamics constraints, or actuator capabilities, easily leading to problems such as infeasible vehicle control, constraint exceeding limits, or control oscillations. Therefore, there are issues of inconsistent collaborative strategies and risks to vehicle executability. On the other hand, if external collaborative strategies contain inappropriate intentions, outdated information, or are tampered with, they may bypass the vehicle's own safety constraint links, increasing the risk of driving control strategies. Therefore, there are issues of risk injection and breach of safety consistency.

[0004] Furthermore, centralized or semi-centralized collaborative strategies rely on core scheduling nodes such as centralized nodes or roadside units, as well as the continuous availability of communication links between centralized nodes or roadside units and the vehicle and other intelligent agents. When core scheduling nodes fail or communication links are abnormal, vehicles are prone to degenerate into unexpected single-vehicle autonomy and trigger conflict escalation. At the same time, in high-density scenarios, the delay in the generation and distribution of external collaborative strategies makes it difficult to meet the timeliness requirements of collaborative decision-making.

[0005] Therefore, vehicle driving control based on existing vehicle driving control methods has problems such as control infeasibility, control risks, control insecurity, and control delay. Summary of the Invention

[0006] This application provides a vehicle driving control method and system. The vehicle includes an intelligent agent collaboration layer that establishes a negotiation session with an external intelligent agent. The negotiation session is verified to obtain verification evaluation information. If the verification evaluation information indicates that the verification evaluation has passed, a negotiation session structure is generated based on the negotiation session and the verification evaluation information. This negotiation session structure is then sent to the task strategy layer. If the task strategy layer determines that the negotiation session structure meets safety constraints and feasibility requirements, it generates target driving control strategy instruction information based on the negotiation session structure and pre-generated driving control strategy instruction information. Thus, compared to the existing method of directly injecting external communication commands into vehicle control, this application, based on the intelligent agent collaboration layer for negotiation session processing, enables negotiation control of external intelligent agents, verifies and evaluates external negotiation sessions, and only adopts negotiation sessions that have passed verification evaluation to generate negotiation session structures. This avoids the transmission of mismatched or risky negotiation sessions to the task strategy layer, preventing the vehicle control strategy from becoming infeasible or triggering risks. It improves the feasibility and accuracy of the target driving control strategy instruction information, providing a safer and more accurate driving strategy for multi-agent collaboration in autonomous driving, and enhancing or ensuring the safety of vehicle driving control. Furthermore, the vehicle's intelligent agent collaboration layer directly negotiates and communicates. This decentralized communication method does not rely on other core communication nodes, which can reduce communication latency, improve the efficiency of generating target driving control strategy instruction information, reduce vehicle control latency, and improve vehicle control real-time performance.

[0007] In a first aspect, embodiments of this application provide a vehicle driving control method applied to a vehicle. The vehicle includes a vehicle driving control system for implementing vehicle driving control. The vehicle driving control system includes an agent collaboration layer and a task strategy layer. The method includes: the task strategy layer determining task strategy decision information corresponding to the vehicle, and generating driving control strategy indication information for guiding vehicle driving based on the task strategy decision information; the agent collaboration layer, when determining that the task strategy layer needs to introduce external agent capabilities, establishing a negotiation session with at least one external agent based on a preset agent communication protocol, performing verification and evaluation processing on the negotiation session to obtain verification and evaluation processing information, and generating a negotiation session structure based on the negotiation session and the verification and evaluation processing information when the verification and evaluation processing information indicates that the verification and evaluation has passed, and sending the negotiation session structure to the task strategy layer. The external agent is an external computing node or external device that has communication interaction and collaborative decision-making requirements with the vehicle driving control system; the task strategy layer, when determining that the negotiation session structure meets safety constraints and feasibility requirements, generating target driving control strategy indication information based on the negotiation session structure and the driving control strategy indication information for use in vehicle driving control.

[0008] By adopting the above technical solution, the task strategy layer determines the task strategy decision information corresponding to the vehicle, and generates driving control strategy instruction information to guide vehicle driving based on the task strategy decision information. When the task strategy layer determines that it needs to introduce external intelligent agent capabilities, the intelligent agent collaboration layer establishes a negotiation session with at least one external intelligent agent based on a preset intelligent agent communication protocol. The negotiation session is then verified and evaluated to obtain verification and evaluation processing information. If the verification and evaluation processing information indicates that the verification and evaluation have passed, a negotiation session structure is generated based on the negotiation session and the verification and evaluation processing information, and this structure is sent to the task strategy layer. In this way, the intelligent agent collaboration layer first verifies and evaluates the negotiation session, and only performs verification and transmission without making decisions or controlling, ensuring that the negotiation session structure sent to the task strategy layer is verified and evaluated successfully. This effectively reduces the interference of risky or insecure negotiation sessions on the task strategy layer, improving the security of the target driving control strategy instruction information. Furthermore, when the task strategy layer determines that the negotiation session structure meets safety constraints and feasibility requirements, it generates target driving control strategy instruction information based on the negotiation session structure and the driving control strategy instruction information for vehicle driving control. In this way, the agent collaboration layer first verifies and evaluates the negotiation session, effectively preventing external negotiation sessions from directly interfering with and controlling the task strategy layer. The task strategy layer retains the final decision-making power. Simultaneously, a negotiation session structure that meets safety constraints and feasibility requirements, along with pre-generated driving control strategy indication information, generates target driving control strategy indication information. This improves the feasibility and accuracy of the target driving control strategy indication information. Furthermore, because the driving control strategy indication information is used to instruct the vehicle driving control strategy, it enhances or ensures the feasibility and accuracy of the driving control strategy used for vehicle driving control. This provides a safer, more implementable, and more accurate driving strategy for multi-agent collaboration in autonomous driving, resulting in better vehicle driving control safety, feasibility, functionality, and accuracy. Moreover, this decentralized approach of the agent collaboration layer, which eliminates the need for external nodes or agent decision-making control, shortens the negotiation session transmission link, accelerates negotiation communication time, and improves the real-time requirements of vehicle driving control.

[0009] In one possible implementation of the first aspect above, the negotiation session is a session message generated based on intent broadcast messages, intent response messages, and consensus prompt messages during multiple communication sessions. The verification and evaluation process includes at least one of the following: semantic security verification and evaluation process; anomaly and injection verification and evaluation process; permission and scope verification and evaluation process; weak consistency verification and evaluation process; time consistency verification and evaluation process; and trustworthiness verification and evaluation process.

[0010] By adopting the above technical solution, the negotiation session is pre-verified and evaluated to obtain corresponding verification and evaluation information. This allows the task strategy layer to determine whether the negotiation session structure meets the safety constraints and feasibility requirements based on the verification and evaluation information, and then determine whether to adopt the negotiation session structure. This ensures the security and accuracy of the target driving control strategy instruction information, reduces vehicle control conflicts and risks from the source, and improves the security and accuracy of vehicle control.

[0011] In one possible implementation of the first aspect described above, the agent collaboration layer and the task strategy layer communicate based on a negotiation fusion interface. The agent collaboration layer generates a negotiation session structure based on the negotiation session and verification evaluation processing information, including: the agent collaboration layer sending the negotiation session and verification evaluation processing information to the negotiation fusion interface; and the negotiation fusion interface, after determining that the negotiation session meets the first verification evaluation condition based on the verification evaluation processing information, performing protocol-level encapsulation processing on the negotiation session and verification evaluation processing information to generate a negotiation session structure. The first verification evaluation condition includes the following conditions: the negotiation session meets the schema verification, the negotiation session is within its validity period, and the risk gating and scope verification of the negotiation session are passed.

[0012] By adopting the above technical solution, the negotiation session and verification evaluation processing information output by the agent collaboration layer are encapsulated into a negotiation session structure that can be received and recognized by the task strategy layer based on the negotiation fusion interface. Furthermore, the verification processing is performed in advance based on the negotiation fusion interface. For negotiation sessions that fail the verification evaluation, no interaction with the task strategy layer is performed directly. This can effectively avoid interference from negotiation sessions that fail the verification evaluation to the task strategy layer and ensure the stability of the driving control strategy instruction information generated by the task strategy layer.

[0013] In one possible implementation of the first aspect described above, the task strategy layer, upon determining that the negotiation session structure meets the security constraints and feasibility requirements, generates target driving control strategy indication information based on the negotiation session structure and driving control strategy indication information. This includes: when the task strategy layer determines that the negotiation session structure meets the first triggering condition, it determines that the entire negotiation session structure meets the security constraints and feasibility requirements, accepts the negotiation session structure, and generates target driving control strategy indication information based on the negotiation session structure and driving control strategy indication information; when the task strategy layer determines that the negotiation session structure meets the second triggering condition, it determines that the negotiation session structure partially meets the security constraints and feasibility requirements, modifies the negotiation session structure, and generates target driving control strategy indication information based on the modified negotiation session structure and driving control strategy indication information.

[0014] By adopting the above technical solution, the negotiation session part of the external intelligent agent meets the security constraints and feasibility requirements. The negotiation session structure is modified, and the target driving control strategy instruction information is generated based on the modified negotiation session structure and the driving control strategy instruction information. This improves or ensures the accuracy of the target driving control strategy instruction information, avoids interference from erroneous, infeasible, or dangerous negotiation session structures with vehicle driving control, and enhances the stability of the task strategy layer.

[0015] In one possible implementation of the first aspect above, the method further includes: when the task strategy layer determines that the negotiation session structure does not meet the security constraints or feasibility requirements, it rejects the negotiation session structure and uses the driving control strategy instruction information for vehicle driving control.

[0016] Using the above technical solution, if the negotiation session structure does not meet the security constraints or feasibility requirements, the negotiation session structure is rejected, and the task strategy layer reverts to the vehicle unit control mode. Only the driving control strategy indication information generated by the task strategy layer is used for vehicle driving control. This rejects the impact of negotiation session structures that fail verification on subsequent driving control strategies and vehicle driving control from the source, thereby improving the stability of single-vehicle driving control.

[0017] In one possible implementation of the first aspect above, the task strategy layer generates target driving control strategy indication information based on the negotiation session structure and driving control strategy indication information, including: updating the driving control strategy indication information based on the negotiation session structure; determining the target sub-agent in the task strategy layer based on the negotiation session structure; generating a target sub-driving control strategy based on the target sub-agent; and generating the target driving control strategy indication information based on the updated driving control strategy indication information and the target sub-driving control strategy.

[0018] By adopting the above technical solution, the driving control strategy instruction information is optimized according to the negotiation session structure, and the target driving control strategy instruction information that satisfies the interaction of multiple intelligent agents is generated, making the intelligent driving function more numerous and more advanced.

[0019] In one possible implementation of the first aspect above, the method further includes: the task strategy layer obtaining security summary information; discarding the negotiation session structure if it is determined that the negotiation session structure conflicts with the security summary information; and determining whether the negotiation session structure meets security constraints and feasibility requirements if it is determined that the negotiation session structure does not conflict with the security summary information; and / or the task strategy layer determining the execution feedback information obtained by the vehicle driving control according to the target driving control strategy instruction information; and downgrading the weight of the negotiation session structure or discarding the negotiation session structure if it is determined that the execution feedback information is not feasible.

[0020] By adopting the above technical solution, the negotiation session structure is constrained within the safe driving range and the executable range of the vehicle based on the security summary information and execution feedback information, thereby ensuring vehicle driving safety.

[0021] In one possible implementation of the first aspect mentioned above, the preset intelligent agent communication protocol is a decentralized A2A communication protocol. The intelligent agent collaboration layer and the external intelligent agent negotiate and communicate based on the decentralized A2A communication protocol. The intelligent agent collaboration layer and the task strategy layer communicate within the vehicle based on the A2A communication protocol. The decentralized A2A communication protocol includes a lifecycle control mechanism. The intelligent agent collaboration layer determines the negotiation session with the external intelligent agent, performs verification and evaluation processing on the negotiation session, and obtains verification and evaluation processing information. This includes: the intelligent agent collaboration layer establishes a negotiation session with the external intelligent agent based on the lifecycle control mechanism, and performs verification and evaluation processing on the negotiation session to obtain verification and evaluation processing information.

[0022] By adopting the above technical solution, the decentralized A2A communication protocol enables multi-round dialogue and verification / evaluation processing between the vehicle and external intelligent agents throughout the lifecycle control process. This allows for automatic dialogue and negotiation with external intelligent agents, and automatic verification and evaluation of the negotiation sessions. The intelligent agent collaboration layer can automatically and effectively verify and evaluate the negotiation sessions with external intelligent agents. Furthermore, since the intelligent agent collaboration layer communicates based on the decentralized A2A communication protocol, it can conduct multi-agent negotiation communication in a decentralized collaborative manner, without relying on centralized nodes or other decision-making nodes to communicate with external intelligent agents. This shortens the communication link, improves negotiation communication efficiency, and enhances the real-time requirements of vehicle driving control.

[0023] Secondly, this application also discloses a vehicle driving control system, which is applied to a vehicle. The vehicle driving control system includes an intelligent agent collaboration layer and a task strategy layer. The task strategy layer is used to determine the task strategy decision information corresponding to the vehicle and generate driving control strategy instruction information to guide the vehicle's driving based on the task strategy decision information. The intelligent agent collaboration layer is used to establish a negotiation session with at least one external intelligent agent based on a preset intelligent agent communication protocol when it is determined that the task strategy layer needs to introduce external intelligent agent capabilities. The negotiation session is then verified and evaluated to obtain verification and evaluation processing information. If the verification and evaluation processing information indicates that the verification and evaluation has passed, a negotiation session structure is generated based on the negotiation session and the verification and evaluation processing information, and the negotiation session structure is sent to the task strategy layer. The external intelligent agent is an external computing node or external device that has communication interaction and collaborative decision-making requirements with the vehicle driving control system. The task strategy layer is used to generate target driving control strategy instruction information based on the negotiation session structure and the driving control strategy instruction information for vehicle driving control, if it is determined that the negotiation session structure meets safety constraints and feasibility requirements.

[0024] Thirdly, this application also discloses a vehicle, including the vehicle driving control system disclosed in the second aspect, for executing the vehicle driving control method disclosed in any of the implementations of the first aspect.

[0025] The relevant beneficial effects of the second and third aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0026] To more clearly illustrate the technical solution of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below.

[0027] Figure 1 This is a schematic diagram of a vehicle driving control system provided in an embodiment of this application;

[0028] Figure 2 This is a schematic flowchart of a vehicle driving control method provided in an embodiment of this application;

[0029] Figure 3 A flowchart illustrating the lifecycle control mechanism provided in this application embodiment;

[0030] Figure 4 This is a schematic diagram illustrating the principle of a vehicle driving control system and method provided in an embodiment of this application. Detailed Implementation

[0031] With the deep integration of the automotive industry and artificial intelligence technology, vehicles have gradually evolved from the stage of assisted driving to advanced intelligent driving. In intelligent driving scenarios, multi-agent collaborative driving (such as vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-network (V2N)) has become a core direction for breaking through bottlenecks and improving traffic efficiency and safety in complex scenarios. For example, scenarios such as multiple vehicles traveling in opposite directions on narrow roads and needing to negotiate the order of yielding; parking scenarios in underground garages where multiple vehicles simultaneously seek parking spaces and negotiate parking routes and allocation; traffic scenarios at unsignalized intersections where multiple vehicles negotiate the order of passage based on communication intentions; adversarial scenarios where multiple vehicles compete for and coordinate the allocation of limited resources such as roads, parking, or charging; and cross-scenario collaborative control scenarios where vehicles negotiate and interact with external intelligent entities such as charging piles, parking equipment, and smart home systems. Examples include battery preheating and power negotiation before charging, automatic parking scheduling after charging, efficient allocation of vacant parking spaces, and the linkage between vehicle and home environment status before travel. In these scenarios, mutual recognition of intentions, negotiation of behaviors, and risk management among intelligent entities cannot achieve global optimization by relying solely on single-vehicle perception and decision-making.

[0032] Existing vehicle control decision-making methods mostly employ a "forced injection of external communication commands" model. These methods are largely centralized or semi-centralized, with cloud-based or roadside units acting as negotiators to generate negotiation schemes and inject them into the target vehicle to interfere with its control decision generation. On one hand, the external collaborative strategies generated by external agents may be incompatible with the vehicle's perceived real-time environment, vehicle dynamics constraints, or actuator capabilities, easily leading to problems such as infeasible vehicle control, constraint exceeding limits, or control oscillations. Therefore, there are issues of inconsistent collaborative strategies and risks to vehicle executability. On the other hand, if external collaborative strategies contain inappropriate intentions, outdated information, or are tampered with, they may bypass the vehicle's own safety constraint links, increasing the risk of driving control strategies. Therefore, there are issues of risk injection and disruption of safety consistency.

[0033] Furthermore, centralized collaboration relies on the cloud or roadside units (RSUs) as the core scheduling node to uniformly collect the status of each agent, generate collaborative strategies, and distribute them to the target vehicle. Semi-centralized collaboration, on the other hand, retains some autonomy in individual vehicle decision-making, achieving collaborative scheduling and conflict arbitration only in localized areas through roadside units. Both architectures attempt to resolve multi-agent conflicts through external intervention. If the core scheduling node fails or the communication link is interrupted, the entire collaborative system will immediately collapse, forcing vehicles to revert to an unexpected single-vehicle autonomous mode, which can easily lead to loss of control. In addition, in high-density scenarios, the end-to-end transmission of multi-agent status data upload, global strategy generation, and command issuance is difficult to meet the millisecond-level decision-making requirements of autonomous driving. Especially in high-density scenarios, conflicts caused by command lag are likely to occur. Furthermore, if the core scheduling node becomes a target for attack, once it is compromised and the strategy is tampered with, it will cause large-scale collaborative accidents, and there is a lack of effective distributed verification mechanisms.

[0034] Therefore, existing vehicle cooperative control methods and systems suffer from low vehicle driving control safety, feasibility, and accuracy, as well as poor real-time performance, which affect the safety, feasibility, real-time performance, and accuracy of vehicle control.

[0035] Based on this, this application discloses a vehicle driving control method and system. When the intelligent agent collaboration layer determines that the task strategy layer needs to introduce the capabilities of an external intelligent agent, it establishes a negotiation session with the external intelligent agent, performs verification processing on the negotiation session, obtains verification evaluation processing information, and when it is determined that the verification evaluation processing information indicates that the verification evaluation has passed, it generates a negotiation session structure based on the negotiation session and the verification evaluation processing information, and sends the negotiation session structure to the task strategy layer. When the task strategy layer determines that the negotiation session structure meets the safety constraints and feasibility requirements, it generates target driving control strategy instruction information based on the negotiation session structure and pre-generated driving control strategy instruction information, so as to control the vehicle driving according to the target driving control strategy instruction information.

[0036] In the implementation of this application, the external intelligent agent is specifically at least one of the following external devices: other vehicle intelligent agents, parking lot infrastructure intelligent agents or road infrastructure intelligent agents, smart home intelligent agents, smart garage intelligent agents, adversarial driving intelligent agents in simulation test environments, or at least one of the following external nodes: cloud nodes, edge computing nodes, etc.

[0037] In this way, the intelligent agent collaboration layer only provides the negotiation session structure to the task strategy layer and does not participate in direct decision-making. Under the premise of maintaining the stability and controllability of in-vehicle decision-making and safety closed loop, it can achieve high semantic negotiation and consensus between vehicles and between vehicles and external intelligent agents, improve the safety, efficiency and system robustness in multi-vehicle interaction, parking collaboration and complex game scenarios, support the natural generation and system-level verification of adversarial driving behavior, and effectively ensure driving safety in multi-agent interaction scenarios.

[0038] Furthermore, the agent collaboration layer engages in negotiation sessions with external agents and performs verification and evaluation on these sessions. This process considers information such as the real-time vehicle environment, vehicle dynamics constraints, and actuator capabilities, improving the consistency of the negotiation sessions. Moreover, the agent collaboration layer first verifies and evaluates the negotiation sessions, and only generates a negotiation session structure when the verification and evaluation pass before sending it to the task strategy layer. This avoids transmitting information that fails the verification and evaluation to the task strategy layer, which could cause decision interference and instability. Additionally, the agent collaboration layer communicates based on a decentralized A2A communication protocol, enabling multi-agent negotiation communication in a decentralized manner. It eliminates the need to rely on centralized nodes or other decision-making nodes to communicate with external agents, shortening communication links, improving negotiation efficiency, and enhancing the real-time performance requirements of vehicle driving control.

[0039] Furthermore, after determining that the negotiation session structure meets the safety constraints and feasibility requirements, the task strategy layer generates target driving control strategy instruction information based on the negotiation session structure and pre-generated driving control strategy instruction information for vehicle driving control. On the one hand, the task strategy layer considers negotiation session structures that meet safety constraints and feasibility requirements, which can improve the feasibility, functionality, safety, and accuracy of vehicle driving control strategies, reduce vehicle driving control risks, and thus improve the feasibility, functionality, safety, and accuracy of vehicle driving control.

[0040] The vehicle driving control method and system provided in this application will be described in detail below.

[0041] like Figure 1 As shown, the vehicle driving control system of this application includes a safety monitoring layer L0, a real-time control layer L1, a task strategy layer L2, and an intelligent agent collaboration layer L3.

[0042] The safety monitoring layer L0 is used to determine the driving safety decision information corresponding to the vehicle, generate safety constraint instruction information based on the driving safety decision information, and send the safety constraint instruction information to the real-time control layer.

[0043] The task strategy layer L2 is used to determine the task strategy decision information corresponding to the vehicle, generate driving control strategy instruction information based on the task strategy decision information, and send the driving control strategy instruction information to the real-time control layer for vehicle driving control.

[0044] Driving control strategy instruction information is used to indicate the next driving mode, control objectives, and phased intentions (i.e., driving control strategy).

[0045] The agent collaboration layer is used to establish a negotiation session with at least one external agent based on a preset agent communication protocol when it is determined that the task strategy layer needs to introduce the capabilities of an external agent. The negotiation session is then verified and evaluated to obtain verification and evaluation information. If the verification and evaluation information indicates that the verification and evaluation has passed, a negotiation session structure is generated based on the negotiation session and the verification and evaluation information, and the negotiation session structure is sent to the task strategy layer.

[0046] Among them, external intelligent agents are external computing nodes or external devices that have communication, interaction and collaborative decision-making needs with the vehicle driving control system;

[0047] The task strategy layer is also used to generate target driving control strategy indication information based on the negotiation session structure and driving control strategy indication information, when it is determined that the negotiation session structure meets the safety constraints and feasibility requirements, for use in vehicle driving control.

[0048] In one implementation, the task strategy layer generates a meta-instruction packet based on the target driving control strategy instruction information and other vehicle control strategy related information, and sends the meta-instruction packet to the real-time control layer.

[0049] The real-time control layer L1 determines the control command generation decision information corresponding to the vehicle, generates vehicle driving control commands based on safety constraint indication information, target driving control strategy indication information (or meta-instruction package) and control command generation decision information, and controls the vehicle driving according to the vehicle driving control commands.

[0050] Furthermore, the real-time control layer is also used to send execution feedback information of the vehicle control commands to the task strategy layer.

[0051] Therefore, based on the L0-L2 architecture, a closed-loop control architecture for autonomous driving decision-making and execution within a single vehicle can be formed.

[0052] In the implementation of this application, the vehicle internal control architecture consisting of L0-L2 adopts a centralized strategy orchestration structure.

[0053] This application proposes a decentralized intelligent agent collaboration layer L3. Based on the L0-L2 autonomous vehicle driving control architecture, the decentralized intelligent agent collaboration layer L3 adopts a decentralized A2A communication mechanism at the collaborative levels of cross-vehicle, cross-roadside, and cross-facilities to achieve high semantic collaborative communication and security verification between the autonomous vehicle system and external autonomous intelligent agents. This expands the cross-vehicle and cross-system collaborative capabilities of the autonomous driving system without disrupting the autonomous vehicle control and safety closed loop.

[0054] In this application, the intelligent agent collaboration layer and the task strategy layer communicate within the vehicle based on the A2A communication protocol. The task strategy layer L2 can generate driving control strategy instruction information that can meet the needs of multi-vehicle driving based on the negotiation session structure generated by the negotiation session between the decentralized intelligent agent collaboration layer L3 and the external intelligent agent, for use in vehicle driving control.

[0055] Furthermore, in this application, the communication principle of the intelligent agent collaboration layer L3 is the decentralized autonomous operation principle, that is, each executor operates independently without relying on a single central control node, and has a verifiable negotiation mechanism. That is, all communication messages in the negotiation session must be verified and evaluated. The verification and evaluation information includes information such as risk assessment, evidence citation, and validity period of the negotiation session. Based on the negotiation session, the vehicle intelligent driving system and the external intelligent agent can form a weak consistency consensus principle. The weak consistency consensus principle means that the vehicle intelligent driving system and the external intelligent agent form a local vehicle driving control consensus within a limited time window. If the negotiation timeout occurs, the level of the external negotiation session will be automatically reduced.

[0056] It should be noted that decentralization means that the intelligent agent collaboration layer can negotiate with external intelligent agents on its own, without relying on other nodes for collaborative negotiation.

[0057] This application adds an intelligent agent collaboration layer (L3) to the existing architecture of the safety monitoring layer (L0), real-time control layer (L1), and task strategy layer (L2). This intelligent agent collaboration layer communicates and interacts with external intelligent agents based on a decentralized intelligent agent collaborative communication method. This collaborative communication method can be likened to building a complete "autonomous driving society." It is no longer limited to the "individual intelligence" of a single vehicle, but rather, through establishing rules, unifying language, and standardizing processes, it enables countless autonomous driving intelligent agents to form an orderly, negotiated, and verified collective intelligence system. Its core operating logic is highly consistent with the collaborative paradigm of "human society." For example, it can ensure that vehicles adhere to the bottom line of "safety laws": each vehicle takes the in-vehicle L0-L2 safety closed loop as an inviolable "social law," and all collaborative behaviors must comply with safety safeguards. Even if consensus is reached, the hard safety rules must not be violated, ensuring that "collaboration always gives way to safety."

[0058] Furthermore, intelligent agents can unify their "interaction and communication language": through standardized information (NegotiationHintBundle carrier) and unconditional consensus (ACK) / conditional negotiation (CONDITIONAL_ACK) response mechanisms, a unified "communication language" is established for all intelligent agents, avoiding misunderstandings and deviations caused by unstructured information, and making the transmission of intent, confirmation of conditions, and consensus-building efficient and unambiguous.

[0059] Furthermore, by establishing a "negotiation resolution mechanism": based on a negotiation state machine that can manage the entire lifecycle, a lifecycle control mechanism is generated, providing a "negotiation channel" for conflicts in complex scenarios. Instead of simply confronting each other (such as cutting in or braking suddenly), multiple vehicles reach a consensus on driving control through multiple rounds of intention interaction and condition compromise, thereby achieving orderly traffic and efficient resource allocation.

[0060] The vehicle driving control system of this application can actively create "social conflicts" (such as malicious lane cutting, sudden lane changes, consensus breakdown and other adversarial scenarios) in a simulation environment by conducting "rule verification exercises". This simulates the interaction behavior of intelligent agents under extreme conditions, and verifies the reliability of "social rules" (cooperation protocols, security mechanisms, decision-making logic) in advance, making up for the shortcomings of scarce real-world scenario data and insufficient coverage of extreme cases.

[0061] In summary, by setting up an intelligent agent collaboration layer, autonomous driving can evolve from "single-vehicle self-consistency" to "group co-governance," thereby achieving a leap in efficiency and robustness of the entire autonomous driving group while ensuring individual safety.

[0062] It should be noted that in this application, the agent collaboration layer L3 only generates negotiation sessions and verification evaluation processing information, does not directly generate control commands, does not bypass the security decisions of L2 or L0, and only provides structured negotiation prompts and external risk signals (i.e., negotiation session structures) to the L2 layer, which then decides whether to adopt the negotiation session structure.

[0063] In the implementation of this application, the decentralized agent collaboration layer L3 communicates with external agents based on a decentralized A2A (i.e., D-A2A) communication protocol (as an example of a preset agent communication protocol).

[0064] The D-A2A communication protocol is an extension protocol built on top of the A2A-Drive decision communication protocol. It is used to support autonomous driving systems to achieve high semantic collaborative communication between multiple agents across systems at the decentralized agent collaboration layer (L3).

[0065] Unlike A2A-Drive, which focuses on decision-making and orchestration within a single vehicle, D-A2A focuses on negotiation and consensus across vehicles, systems, and autonomous agents. Its core objective is not to generate control commands, but to provide verifiable, rejectable, and degradeable external collaborative information for single-vehicle decision-making systems.

[0066] The negotiation session between the external intelligent agent and the intelligent agent collaboration layer inside the vehicle consists of session messages generated from intent broadcast messages, intent response messages, and consensus hint messages during multiple communication sessions. In other words, the messages in the multi-round communication session are semantic messages, and the semantic message types are intent broadcast messages, intent response messages, and consensus hint messages.

[0067] The intent broadcast message declares the agent's behavioral intent and its validity period within the current time or a future time window. This message does not contain control variables, but only describes the intent type, credibility, and time constraints. The intent response message describes the receiver's response to the intent broadcast message during multi-agent interaction. This response includes at least acknowledgment, rejection, or conditional acknowledgment, and may carry additional constraints and validity information. The consensus prompt message describes the candidate consensus result obtained by aggregating intent broadcast and intent response messages from multiple participants during multi-agent interaction. This candidate consensus result includes at least the negotiation participants, suggested execution order, resource allocation / transfer relationships, time constraints, and consensus status identifiers. All messages use a unified encapsulation format and support trace identifiers (Trace_id / Span_id), latency and validity constraints, priority identifiers, and integrity checks.

[0068] Thus, the vehicle driving control system provided by the implementation method of this application includes a task strategy layer and an intelligent agent collaboration layer set inside the vehicle. The task strategy layer generates a task strategy decision request (including task strategy decision information) based on the vehicle's current driving task, environmental summary information, and system status information. It then generates a meta-instruction package (including driving control strategy indication information) to guide vehicle driving based on the task strategy decision information. When the intelligent agent collaboration layer determines that the strategy decision request of the task strategy layer requires the introduction of external intelligent agent capabilities, it establishes a negotiation session with at least one external intelligent agent based on a preset intelligent agent communication protocol. It then verifies and evaluates the description of the external intelligent agent capabilities involved in the negotiation session, the negotiation session latency characteristics, and the security level to obtain verification and evaluation processing information. The negotiation session result that has passed the verification and evaluation processing is encapsulated into a structured negotiation session structure and sent to the task strategy layer. When the task strategy layer determines that the negotiation session structure meets the security constraints and feasibility requirements, it combines the negotiation session structure and its own driving control strategy indication information to generate driving control strategy indication information for vehicle driving control. In this way, by adopting only the verified and evaluated negotiation session structures to participate in the generation of driving control strategies, while ensuring the consistency of centralized orchestration of driving control decisions and safety constraints within the vehicle (i.e., vehicle driving control based on the L0-L2 layers), controlled collaborative decision-making between the vehicle and external intelligent agents is achieved (i.e., L2 optimization of driving control strategies based on L3 negotiation session structures). This improves the stability, functionality, real-time performance, and feasibility of driving control strategies, thereby enhancing the safety and feasibility of vehicle driving.

[0069] like Figure 2 As shown, the vehicle driving control method of this application includes the following steps.

[0070] S100, the task strategy layer determines the task strategy decision information corresponding to the vehicle, and generates driving control strategy instruction information to guide the vehicle's driving based on the task strategy decision information.

[0071] For example, the task strategy decision information is also known as the vehicle's planning snapshot, including goal specification information, world summary information, system state information, safety summary information, and execution feedback information from the previous vehicle driving control operation. The task strategy layer generates task strategy decision information by acquiring semantic task information (including navigation / parking / driving style information), structured world summary information, system state information, safety summary information sent from the safety monitoring layer, and execution feedback information sent from the real-time control layer. Based on the task strategy decision information, the main agent and at least one sub-agent generate driving control strategy instruction information.

[0072] S200: When the intelligent agent collaboration layer determines that the task strategy layer needs to introduce the capabilities of an external intelligent agent, it establishes a negotiation session with at least one external intelligent agent based on a preset intelligent agent communication protocol, performs verification and evaluation processing on the negotiation session, obtains verification and evaluation processing information, and generates a negotiation session structure based on the negotiation session and the verification and evaluation processing information when the verification and evaluation processing information indicates that the verification and evaluation has passed. The negotiation session structure is then sent to the task strategy layer. The external intelligent agent is an external computing node or external device that has communication interaction and collaborative decision-making needs with the vehicle driving control system.

[0073] In this application, to ensure that decentralized negotiation does not introduce uncontrollable risks and to address common issues in cross-vehicle and cross-system collaboration such as "inconsistent failures, state drift, difficulties in revocation and rollback, and undetectable consensus failures," the D-A2A communication protocol introduces a negotiation lifecycle control mechanism. This mechanism provides unified management of the entire negotiation process, including initiation, advancement, agreement, execution, revocation, and failure, and ensures that negotiation information always meets the engineering constraints of "verifiability, rejection, degradation, and replayability." Specifically, the D-A2A communication protocol determines the negotiation session with the external intelligent agent based on the negotiation lifecycle control mechanism and performs verification and evaluation processing on the negotiation session to obtain verification and evaluation information, thereby enabling the management of the initiation, advancement, agreement, execution, revocation, and failure of the negotiation session.

[0074] For example, when the agent collaboration layer receives a communication establishment request from an external agent, it determines that the task strategy layer needs to introduce the capabilities of the external agent. The capabilities of the external agent include the type of the external agent (e.g., vehicle, roadside equipment, garage system), negotiation intent, consensus information, and other information.

[0075] Alternatively, when the agent collaboration layer receives an external agent negotiation introduction request from the task strategy layer, it determines that the task strategy layer needs to introduce external agent capabilities. The task strategy layer's external agent negotiation introduction request is obtained by identifying the current driving scenario based on the scenario sub-agents included in the task strategy layer. For example, it might determine that the vehicle is in a multi-vehicle yielding scenario, an intelligent parking scenario, or a narrow road meeting scenario. If it determines that interaction with an external agent is required, it generates an external agent negotiation introduction request and sends it to the agent collaboration layer, enabling the agent collaboration layer to establish negotiation communication with the external agent based on the D-A2A communication protocol.

[0076] Furthermore, a negotiation session with an external intelligent agent is determined based on the negotiation lifecycle control mechanism, and the negotiation session is verified and evaluated to obtain verification and evaluation processing information. This includes: invoking the negotiation session model based on the negotiation lifecycle control mechanism, establishing a negotiation session with the external intelligent agent based on the negotiation session model, and performing verification and evaluation processing on the negotiation session based on the verification and evaluation mechanism to obtain verification and evaluation processing information.

[0077] In this application, the session is managed through session_id+epoch based on the negotiation lifecycle control mechanism. It has built-in throttling, jitter suppression, execution verification and evaluation, and execution termination mechanism for multiple scenarios to solve engineering pain points such as "consensus cannot be executed, negotiation jitter, and no fallback for anomalies". All states are internal execution logic and do not need to be exposed to the outside. The core implementation is a closed-loop capability that makes the negotiation process controllable, the execution result fallback, and the abnormal situation can be terminated.

[0078] Furthermore, in addition to the core aspects of "one-time / revocable negotiation, timeout handling, and consensus validity testing," this mechanism also addresses the following five types of essential engineering issues.

[0079] First, there's the issue of negotiation thash: In scenarios like narrow road encounters or parking resource contention, agents may frequently issue conflicting intentions, leading to repeated switching of L2 strategies. By using a negotiation lifecycle control mechanism with session-level throttling and versioning management, we can prevent "repeated probing" from escalating into system-level thash, ensuring strategy stability and achieving stable negotiation messages across multiple rounds.

[0080] Second, there is the issue of concurrent session conflict: the same agent may participate in multiple negotiations simultaneously (such as simultaneously meeting the car in front or negotiating a parking space with a garage). Based on the negotiation lifecycle control mechanism, through session isolation and scope constraints, cross-session information interference can be prevented, ensuring that each negotiation is independent and controllable, and achieving negotiation session isolation.

[0081] Thirdly, there is the risk of out-of-order and replay: cross-system communication is susceptible to message out-of-order issues, delays, and replay attacks. A negotiation-based lifecycle control mechanism, relying on a combination of "session_id + epoch + monotonic timestamp + validity_window," achieves bounded timeliness control and orderly integration, mitigating these risks at the source.

[0082] Fourth, partial consensus ≠ feasibility: Even if multiple parties reach a consensus, it may still fail to be implemented due to L1 execution infeasibility (such as exceeding dynamic constraints) or L0 risk transition (such as sudden obstacles). A negotiation lifecycle control mechanism supports "revocation / rollback of the execution phase after consensus is reached," forming a complete closed loop.

[0083] Fifth, the semantic ambiguity of commitments leads to unclear responsibilities (Commitment Ambiguity): In traditional collaboration, commitments such as "yield" and "priority" lack clear semantic definitions (e.g., immediate execution / conditional execution). Based on the negotiation lifecycle control mechanism, a structured encapsulation of "commitment type + conditional constraints + validity period" transforms ambiguous commitments into verifiable objects, facilitating L2 execution of accept / modify / reject decisions while simultaneously meeting auditing and responsibility attribution requirements.

[0084] Based on this, the D-A2A protocol of this application defines a negotiation lifecycle control mechanism, which defines a negotiation session model to define a complete negotiation as a "negotiation session". Each session is identified by a unique session_id. Within a session, multiple rounds of negotiation are managed through epoch (version number / round number), breaking the limitation that "one negotiation equals one message".

[0085] In other words, based on the negotiation session model, it supports multiple rounds of advancement. Negotiation is not a single message interaction; it can achieve intent updates, condition corrections, and consensus iterations through epoch increments. It can flexibly manage permissions, meaning any participant can initiate intent updates, commitment revocations, or session restarts. It can also adapt to decentralized collaboration characteristics and can automatically filter expired information. In other words, the L2 layer can select the latest valid negotiation result based on the epoch, automatically downgrade or discard information from old rounds, and avoid interference from expired data.

[0086] The implementation method of this application defines a negotiation lifecycle control mechanism that requires each communication message in a negotiation session based on a negotiation session model to carry the following core fields to ensure that the session is traceable and manageable: session_id: a unique identifier for the session (generated by the initiator, and can be synthesized in multi-party negotiation scenarios); epoch: the session round number (strictly incremental, used to distinguish between new and old negotiation content); validity constraint: validity_window (validity window) or valid_for_ms (valid duration), defining the effective scope of the negotiation product; hard deadline: deadline_ms, the final time limit for the negotiation result of this round to enter L2 fusion, which automatically expires after the timeout; audit identifier: trace_id / span_id, aligned with the audit link of the L2 autonomous driving system, supporting full-process playback and problem tracing.

[0087] Furthermore, each message in the negotiation session is subjected to verification and evaluation processing to obtain corresponding verification and evaluation processing information. The verification processing includes semantic security verification and evaluation processing, anomaly and injection verification and evaluation processing, and permission and scope verification and evaluation processing. The corresponding verification and evaluation processing information includes semantic security check information, anomaly and injection detection information, and permission and scope verification information. Furthermore, the verification and evaluation processing also includes at least one of priority evaluation processing, scenario mode evaluation processing, negotiation intent evaluation processing, weak consistency verification and evaluation processing, time consistency verification and evaluation processing, trustworthiness verification and evaluation processing, and risk verification and evaluation processing.

[0088] Semantic security verification and evaluation processes include intent type verification and evaluation, risk level verification and evaluation, scenario consistency verification and evaluation, and validity period verification and evaluation. Anomaly and injection verification and evaluation processes include historical behavior consistency verification and evaluation, and cross-agent intent... Figure 1 Consistency verification and evaluation processing, timing verification and evaluation processing. Permission and scope verification and evaluation processing includes capability verification and evaluation processing of external intelligent agents, and intent verification and evaluation processing.

[0089] The credibility verification and evaluation information is obtained based on time consistency characteristics, scenario consistency characteristics, and historical behavior consistency characteristics.

[0090] like Figure 3 As shown, in order to achieve full-link control from negotiation to implementation, a negotiation lifecycle control mechanism is generated by defining a 6-stage lifecycle state machine, covering normal flow and exception fallback, and solving engineering problems such as consensus reaching a point where execution is impossible and there is no way to handle exceptions.

[0091] S0: INIT (Session Initialization), triggered when the vehicle enters a negotiable scenario (such as narrow road encounters, Automated Valet Parking (AVP) space allocation, access control, etc.), or when an external intelligent agent initiates a collaborative request (such as a parking garage facility summoning a vehicle). The corresponding output includes: a unique session_id; and configured core session parameters, including scope (negotiation scope, such as intersection / garage number), participants (candidate list of participants), and policy (negotiation strategy, including maximum number of rounds, latency budget, and minimum confidence threshold). If no valid negotiable scenario or no participants are found during this step, initialization terminates directly, and negotiation is not initiated.

[0092] It should be noted that in the S0 phase, L3 needs to verify the following information: permission and scope verification (including participant permission verification and negotiation scope validity verification), and scenario consistency pre-verification. If the verification fails, the initialization will be terminated directly, and session_id will not be created.

[0093] S1: ANNOUNCE (Intent Broadcast), core action: the initiating agent publishes an intent broadcast message, declaring the behavioral intent and constraint prompts within the future time window. Constraints include the requirement to bind to the validity window, support for subsequent new epochs to overwrite and update the intent, and realize dynamic correction. The corresponding failure handling mechanism is: if the broadcast message verification fails, the sender exceeds the authority, or the intent does not match the current scenario, the message is directly discarded, the session stays at S0, and does not advance to the next stage.

[0094] It should be noted that in the S1 phase, L3 needs to perform the following checks: full-dimensional semantic security check (i.e., semantic security check processing), sender permission and scope check, and timing and replay basic check. If the check fails, the broadcast message is discarded, the session remains in S0, and does not advance to S2.

[0095] S2: NEGOTIATE (Response and Condition Negotiation) Participants return intent response messages to the initial intent broadcast message. Intent response message response types include unconditional acknowledgment (ACK), rejection (REJECT), and conditional acknowledgment (CONDITIONAL_ACK). If intent conflicts exist, either party can publish a modified intent in a new epoch (e.g., changing GO_FIRST to SHORT_STOP(t)), enabling multi-round game theory. A de-jitter mechanism is implemented: within a fixed time window, if a participant repeatedly changes its intent beyond a threshold, a thrash_flag is triggered, reducing the session's credibility or directly terminating the negotiation to avoid a stalemate. A flow rule is executed: if at least one party returns ACK / CONDITIONAL_ACK, proceed to S3; if a REJECT is returned, jump directly to S6 (ABORT branch).

[0096] It should be noted that ACK and CONDITIONAL_ACK are positive response types from the participants to the initiator's intention to broadcast a message (as opposed to REJECT), and are the basis for reaching a consensus among multiple parties. Both are bound to validity_window and epoch, supporting subsequent correction / reversal, and the response result will serve as the core basis for the negotiation engine to generate S3 consensus prompt messages.

[0097] It should be noted that in the S2 phase, L3 needs to perform the following verifications: semantic security checks on response messages, real-time detection of anomalies and injections (e.g., behavior consistency / timing checks), verification of responder permissions, and detection of valid deadlines. If the verification fails, the abnormal response message is discarded, triggering the thrash_flag reduces the trustworthiness or terminates the session, and a full REJECT jumps to S6 (ABORT).

[0098] S3: PROPOSE (Consensus Proposal Formation) transforms fragmented intent interaction messages from multiple rounds (including intent broadcast messages and intent response messages) into standardized consensus prompt messages (also known as proposal intents), avoiding message stacking and achieving protocol-based management of the negotiation state. Specifically, the negotiation engine aggregates the intent and response messages of all participants to generate structured Consensus Proposals (candidate consensus prompt messages), clearly defining core results such as the order of passage, resource locking, and time slice allocation. It sets commitment type definitions (all commitments do not bypass the L0 / L1 security and execution layers): SOFT (soft commitment): only a suggestion of order, allowing adoption after L2 layer modification; CONDITIONAL (conditional commitment): consensus only takes effect when preset measurable conditions are met; HARD-LIMITED (limited hard commitment): strictly enforced within the validity period, but requires passing L0 security verification and L1 feasibility verification.

[0099] It should be noted that in the S3 stage, the following verifications are required: cross-agent consistency comparison, negotiation intent evaluation processing, semantic security check processing of proposal intent, permission and scope verification processing, final identification of abnormal features, risk assessment processing, and credibility assessment processing. If the verification fails, the strategy is marked as "high risk" and its credibility score is reduced for reference by the L2 task decision layer.

[0100] S4: CONSENSUS (Weak Consensus / Conflict Determination) Based on candidate consensus proposals, this stage performs a weak consensus assessment, outputting weak consensus assessment information (Consensus Hint) and marking the core states of consensus_state: REACHED (Full Consensus): All participants agree to the proposal; PARTIAL (Partial Consensus): Core participants agree, some participants do not respond / remain neutral; CONFLICT (Conflict): The intentions of the multiple parties cannot be reconciled, and there is no valid proposal. It also outputs time constraints: If the REACHED / PARTIAL state is not reached within the negotiation deadline, it directly jumps to S6 (TIMEOUT branch). The key rule in this stage is that all consensus is only effective within the validity_window, and any participant can actively withdraw their agreement. Furthermore, any withdrawal request from any participant must pass permission and scope verification and throttling constraints. Withdrawal requests that fail the verification assessment do not trigger session state changes, and there is no "irrevocable" consensus.

[0101] The weak consistency verification and evaluation process is to verify and evaluate the degree of consensus of the negotiation session and output a consensus state identifier to determine the degree of achievement between the external agent and the agent collaboration layer.

[0102] It should be noted that the following verifications are required in phase S4: weak consistency assessment, scenario consistency assessment of consensus results, time consistency assessment, risk assessment, and secondary review of high-risk strategies. If the verification fails, it will be marked as CONFLICT. If no consensus is reached within the time limit, it will jump to S6 (TIMEOUT).

[0103] S5: EXECUTE-WINDOW (Execution Window Observation / Maintenance) addresses the core engineering problem of "consensus reached but execution not possible," achieving closed-loop linkage between negotiation results and execution feedback. Within the consensus validity period, the L2 layer executes Accept / Modify / Reject decisions on consensus prompts, writing all results to the NegotiationDecisionRecord audit log. Simultaneously, it monitors L1ExecFeedback and L0SafetySummary in real time, triggering immediate control: if L1 verification fails (i.e., execution is deemed infeasible due to excessive tracking error, executor saturation, or trajectory solving failure), a rollback policy is triggered, either reversing the execution or rolling back the policy. If L0 safety fails (i.e., a risk transition or prohibited mode is triggered), the consensus impact is immediately reversed, and a degradation policy is initiated. If there are no execution anomalies within the validity period, the process jumps to S6 (EXPIRE branch) upon expiration; if verification fails, it immediately jumps to S6 (ABORT / REVOKE branch).

[0104] It should be noted that the following verifications are required in the S5 phase: continuous monitoring of the consistency of the participants' historical behavior, secondary detection of replay and injection of negotiation messages (anomaly and injection detection and handling), if an anomaly is detected, the rollback_policy is triggered, and the process jumps to S6 (REVOKE / ABORT).

[0105] S6: EXPIRE / REVOKE / ABORT (Expiration / Revocation / Termination) provides a fallback mechanism for termination across all negotiation scenarios, ensuring all branches revert to the single-vehicle autonomous closed loop and guaranteeing safety with no residual risks. Branch termination rules include: 1. EXPIRE (Automatic Expiration): The validity window expires, the consensus automatically expires, and there are no abnormal audit records; 2. REVOKE (Active Revocation): Any party actively sends a Revoke / Cancel event (epoch increments synchronously), revoking its own commitment and triggering negotiation termination; 3. ABORT (Abnormal Termination): Triggered when malicious injection, replay attacks, unauthorized operations, continuous conflicts, participant loss of contact, or when the negotiation round exceeds the threshold or a full REJECT is executed. A unified fallback action: Regardless of the termination method, immediately exit the negotiation process and revert to the single-vehicle L0-L1-L2 native autonomous closed loop; L2 / L0 can trigger a SHORT_STOP(t) short-stop observation or a conservative driving strategy to ensure driving safety.

[0106] It should be noted that the following verifications are performed in the S6 phase: verification of the legality of the termination reason, updating the risk level of the agent that terminates abnormally, and updating the credibility profile of the participants if there is an abnormal termination, and prioritizing the restriction of their permissions in subsequent negotiations.

[0107] In the implementation of this application, the normal flow path for the negotiation session is: S0→S1→S2→S3→S4→S5→S6 (EXPIRE).

[0108] In this implementation, the session ID is used as the granularity, and multiple rounds of updates are supported through epochs. Each round is bounded to a deadline_ms and a validity_window to achieve bounded negotiation and bounded impact. Any participant can send a Revoke / Cancel event at any epoch to revoke a previous commitment, which must include a reason code and an effective time. The L2 side synchronously resets the zeroing / degradation negotiation prompts the impact, triggering rollback / degradation. If a REACHED or PARTIAL consensus is not reached within the negotiation deadline, the session is marked as EXPIRED / CONFLICT; the L2 defaults to rejection or corrects to a conservative strategy (short stop / low-speed creep / single-vehicle planning), automatically degrading to a single-vehicle closed loop without affecting functional safety. The validity of consensus prompt messages included in the negotiation session is dually controlled by the validity_window and the epoch. They automatically expire upon expiration, become invalid when overwritten by a new epoch, become invalid immediately upon revocation, or trigger execution invalidation and revocation if the execution phase is infeasible.

[0109] Furthermore, in the implementation of this application, to adapt to the existing A2A-Drive decision orchestration mechanism, the lifecycle control outputs two types of standardized events (both in the form of prompts, not directly controlled), achieving seamless integration with the L2 layer: Negotiation Rollback Event: Triggering conditions include consensus revocation, execution infeasibility, risk transition, participant disconnection, replay / injection detection, etc.; Expected actions include revoking the impact of negotiation prompts, switching to a conservative strategy, short-stop detection, and re-initiating the session. Negotiation Degrade Event: Triggering conditions include persistent negotiation conflicts, timeout, exceeding the jitter threshold, and credibility falling below the threshold, etc.; Expected actions include degrading to single-vehicle autonomy, reducing external negotiation dependence, and extending the observation window, etc.

[0110] When handling the two types of events mentioned above, the L2 orchestration kernel strictly follows the existing system's principles of "budget slicing, timeout discarding, deterministic output, and replayable auditing," and writes the processing results into the trace to support offline regression testing and attribution of responsibility.

[0111] Furthermore, in the implementation method of this application, to avoid decentralized negotiation information becoming a source of risk in the bicycle safety closed loop, D-A2A introduces an anomaly handling mechanism throughout the protocol operation and L3→L2 fusion process. Its core objective is that when external negotiation information is unreliable, unavailable, or unable to reach a consensus, the system can automatically isolate the risk impact, generate auditable anomaly markers and degradation suggestions, and ensure that the L2–L1–L0 bicycle closed loop remains stable and controllable without affecting functional safety.

[0112] Therefore, the negotiation lifecycle control mechanism also defines an anomaly handling mechanism. The principle of this mechanism is that L3's verification and evaluation information is only input to L2 in the form of prompts, without directly driving vehicle control. It must pass five stages: schema verification, validity period verification, scenario consistency verification, permission and scope verification, and anomaly and injection detection. Failure to pass any stage results in rejection of the fusion process. No anomaly will directly change vehicle control execution; the final decision is still subject to dual gating by L0 safety constraints and L1 feasibility feedback, upholding the bottom line of single-vehicle safety. When an anomaly occurs, the L3 layer output will carry clear anomaly flags and reason codes, triggering corresponding rollback / degradation event prompts for L2 layer to process according to the Accept / Modify / Reject standardized process. All operations are written to the audit log, achieving end-to-end traceability.

[0113] In other words, in any abnormal L3 negotiation scenario, the system automatically degrades to a single-vehicle L2–L0 closed-loop operation mode. The L3 negotiation information does not have a mandatory impact on the execution of vehicle control, thus ensuring that functional safety is not affected by abnormal interference in the coordination process.

[0114] Specifically, if the agent collaboration layer determines from the negotiation session that the current negotiation scenario is a scenario where a malicious agent repeatedly broadcasts conflicting intentions, that is, when it detects that the same external agent frequently changes its intentions, publishes contradictory negotiation content, or induces information within a short time window, it suppresses the risk through session-level control. For example, it sets a throttling mechanism for high-frequency intention changes of the same session_id, marks it with a thrash_flag, and simultaneously lowers the agent's credibility score. For agents with continuous conflicts and frequent anomalies, it triggers scope restriction (only allowing declarations of low-risk intentions) or directly rejects its subsequent negotiation input. The L2 layer executes the Reject operation by default, or Modify uses conservative strategies such as short-stop detection and maintaining single-vehicle planning. All processing results are written to the audit log to retain the basis for accountability.

[0115] If the agent collaboration layer determines that the current negotiation scenario involves delayed, replayed, or forged negotiation messages based on the negotiation session, that is, to address risks such as message out-of-order delivery, delayed arrival, replay attacks, and forgery / tampering that may occur in cross-system communication, risk isolation is achieved through multiple verifications. For example, a hard timeliness gate is constructed using timestamp, deadline_ms, and validity_window, and expired messages are directly discarded and do not participate in decision fusion; negotiation rounds are managed by session_id + epoch, and messages from old epochs are automatically invalidated to avoid historical information interfering with current decisions; for messages that trigger anomaly detection, corresponding anomaly_flags are marked (such as REPLAY_SUSPECT / replay suspicious, TIMESTAMP_ANOMALY / time abnormal, INTEGRITY_FAIL / integrity verification failed), and the L2 layer rejects by default to ensure that network attacks or abnormal transmissions do not affect the single-vehicle safety closed loop.

[0116] If the agent collaboration layer determines from the negotiation session that the current negotiation scenario is one where consensus cannot be reached for an extended period, i.e., the negotiation cannot form a weak consensus within the limited time window (such as multi-vehicle stalemate, resource contention, or mutual rejection), it will handle the situation according to the lifecycle timeout policy. For example, the L3 layer will output consensus_state=CONFLICT (conflict) or EXPIRED (expiration), along with a clear downgrade_policy (degradation policy). The L2 layer will execute Reject or Modify operations based on the budget and deterministic policy, switching to conservative mode, short-term stop, yielding policy, or single-vehicle planning, while recording the failure reason code (such as RESOURCE_CONFLICT / resource conflict, TIMEOUT / timeout, MUTUAL_REJECT / mutual rejection). If the conflict persists, a NegotiationDegradeEvent will be triggered to reduce the system's dependence on external negotiation and maintain the stable operation of the single-vehicle autonomous mode.

[0117] If the agent collaboration layer determines from the negotiation session that the current negotiation scenario involves the complete loss of contact or unavailability of the external agent, that is, when the external agent is lost, the road / garage facilities are unreachable, or the negotiation communication link is interrupted, it will be handled according to the availability degradation mechanism. For example, the L3 layer will mark the corresponding session as ABORT (terminated) or UNAVAILABLE (unavailable) and immediately stop outputting new negotiation prompts; the L2 layer will automatically fall back to the single-vehicle decision-making strategy driven by the vehicle's Planning Snapshot, which does not rely on external collaborative input at all; if in scenarios requiring low-risk strategies, such as passing each other in narrow passages, the L2 layer can adopt short-stop or conservative passage strategies under L0 / L1 gating to ensure basic driving safety.

[0118] In other words, the core principles for abnormal negotiation scenarios in this application are anomaly isolation, auditability, and no impact on the single-vehicle safety closed loop. Specific strategies are developed for typical abnormal scenarios. For malicious agent conflict intent, jitter is suppressed through throttling, credibility downgrading, and scope restriction. The L2 layer adopts a conservative strategy by default. For message delays / replays / forgery, risks are filtered through timeliness gating, round management, and anomaly marking; expired / suspicious messages are directly rejected. For consensus failures, the status is marked as conflict / expired after timeout, automatically reverting to the single-vehicle strategy to reduce reliance on external negotiation. For external agent disconnection issues, the session is marked as terminated, negotiation prompts are stopped, and the system reverts to the single-vehicle decision closed loop.

[0119] In the implementation of this application, in order to prevent high semantic negotiation messages from becoming a source of system security risk, the D-A2A communication protocol introduces a hierarchical security verification mechanism during protocol operation. As mentioned above, the negotiation session is verified, including at least one of the following verification processes.

[0120] Semantic security verification and assessment: This process filters negotiation messages that are formatted correctly but semantically invalid, mismatched in context, or have abnormal timeliness, ensuring that all messages entering the process have valid semantics that are context-appropriate. By verifying the intent type, risk level, context consistency, and validity period of the negotiation session, semantic security verification and assessment information such as the intent type, risk level, context consistency, and validity period of the negotiation session is obtained.

[0121] Specifically, the following checks are performed: Intent type validation: Validating whether the declared intent_type is a type allowed in the current scenario (e.g., declaring the "parking space lock" intent is prohibited in narrow road meeting scenarios); Risk level matching: Validating whether the risk identifier of the negotiated message conflicts with the current vehicle's L0 risk level (e.g., if L0 has triggered high risk, rejecting high-risk intents such as "go first"); Scenario consistency validation: Validating whether the message's map_region_ref / scope is consistent with the vehicle's currently perceived driving scenario, preventing cross-scenario message interference; Timeliness validity validation: Validating whether validity_window / deadline_ms is reasonable (e.g., validity period is not less than 0, deadline is later than the current timestamp), filtering out expired / ineffective messages.

[0122] The execution phases for semantic security checks are S0 initialization pre-verification, S1 intent broadcast reception verification, and S2 response message admission verification. If any stage fails verification, the message is discarded.

[0123] Anomaly and injection verification and evaluation processing: Through historical behavior consistency analysis, cross-agent consistency comparison and time sequence verification, the results of behavior consistency analysis, cross-agent consistency analysis and time sequence verification are obtained to identify abnormal negotiation behaviors such as malicious injection, replay attacks, behavior jitter, and cross-agent conflicts, and to prevent risks introduced by malicious agents or communication anomalies.

[0124] Specifically, behavioral consistency analysis involves continuously tracking the frequency of intent changes and commitment fulfillment rates among participants. If intents are repeatedly changed within a short period (triggering the thrash flag) or if historical commitments severely conflict with current intents, the agent's credibility score is lowered. Cross-agent consistency comparison involves cross-validating the declarations of multiple agents in the same negotiation scenario. If significant contradictions occur (e.g., A declares "yield," while B declares A "go first"), it is marked as an anomaly and a secondary verification is triggered. Timing and replay verification uses session_id + epoch + monotonic timestamp to filter duplicate old messages and out-of-order messages to prevent replay attacks. It also verifies whether the message timing conforms to state machine rules (e.g., submitting an S3 proposal before completing S2 negotiation) to prevent illegal injection. Anomaly feature identification identifies malicious injection features such as high-privilege intents without reasonable justification and intents exceeding vehicle capabilities (e.g., declaring "high-speed passage" in a low-speed parking scenario).

[0125] The specific execution phase of anomaly and injection verification and evaluation processing includes real-time monitoring during the S2 multi-round negotiation process and cross-validation before the S3 consensus proposal is generated. If anomalies are detected, the credibility is reduced or the proposal is marked as "high risk".

[0126] Permission and scope verification and evaluation processing; strictly limit the scope of intent declaration and negotiation scope of different types of intelligent agents (i.e., external intelligent agent capability verification and evaluation processing and intent verification and evaluation processing) to obtain permission and scope verification and evaluation information and prevent unauthorized operations (such as ordinary vehicles declaring "road closed" and garage facilities declaring "vehicles give way").

[0127] Specifically, the system binds agent types and permissions: a whitelist of declarable intents is predefined for each type of agent (vehicles, garage facilities, roadside units, pedestrian terminals, etc.), and intents not on the whitelist are directly judged as unauthorized; strict scope isolation: the system verifies whether the agent's declared intent is within its jurisdictional scope (e.g., garage facilities can only declare intents for parking spaces / access control within the garage, not intents for road access); the scope of the negotiation message must be consistent with the scope of the session initialization to prevent cross-domain operations; and intent permission is hierarchical: high-risk intents (such as "resource monopoly" and "forced passage") are subject to hierarchical permission control, and only authorized agents can declare them, and they must be accompanied by permission credentials.

[0128] The execution phase of the permission and scope verification and evaluation process specifically includes S0 participant access verification, S1 intent broadcast publication verification, and S2 response message reception verification. Unauthorized messages are directly discarded, and the sender is marked as "high risk".

[0129] It should be noted that the above verification mechanism is only used to assess the credibility of the negotiated information. Its output is provided to the L2 decision layer in the form of a prompt and does not directly affect the execution of vehicle control.

[0130] Valid Deadline Detection and Processing: Determine the intent deadline declared by the external agent to obtain the valid deadline, and check whether the valid deadline has expired. If it has expired, the negotiation process is rejected.

[0131] Furthermore, the intent broadcast messages included in the negotiation session undergo time consistency verification evaluation, scenario consistency verification evaluation, historical behavior consistency verification evaluation, and credibility verification evaluation. The credibility verification evaluation information is obtained based on the time consistency verification evaluation information, scenario consistency verification evaluation information, and historical behavior consistency verification evaluation information.

[0132] For example, in the D-A2A decentralized collaborative architecture, the intent broadcast message (S1 phase) serves as the information source for the entire negotiation process, and its credibility directly determines the security and effectiveness of subsequent collaborative decisions. For each external intent message Mi, an intent credibility scoring function is constructed. Credibility is accurately modeled through consistency evaluation across three dimensions: time, scenario, and historical behavior. Simultaneously, the scoring result is deeply bound to the negotiation lifecycle state machine, serving as the core basis for S1 message admission, S2 negotiation weights, and S3 proposal generation. Finally, standardized intent credibility scoring information is output (as an example of credibility verification and evaluation information), providing a quantifiable reference for L2 layer Accept / Modify / Reject decisions.

[0133] In the implementation method of this application, the intent credibility score information is obtained through the following method:

[0134] = (

[0135] in, For the credibility scoring information of intent, This refers to message freshness, also known as time consistency characteristic information. This refers to the time decay factor corresponding to the time consistency feature information. For scene consistency feature information, The scene consistency factor corresponds to the scene consistency feature information. For historical scene consistency feature information, This refers to the historical behavior consistency factor corresponding to the historical scene consistency feature information. The message can declare a risk level. ( This allows you to declare a risk level correction function corresponding to the risk level of a message.

[0136] It should be noted that the intent credibility scoring information Normalize to [0,1] or [0,100], and use clamping to ensure consistent threshold determination.

[0137] The intent broadcast messages of the negotiation session are verified based on the credibility modeling mechanism of intent broadcast.

[0138] Among them, the Temporal Consistency Evaluation is performed on the intent broadcast message to obtain the temporal consistency verification evaluation information. This is mainly aimed at the latency and out-of-order issues of cross-system communication. Based on the time difference between the message generation time and the current system time, a weight that decays over time is applied to the intent message, so that the intent of expired / delayed messages will automatically reduce its impact in subsequent negotiation and integration processes, and avoid historical information from causing undue interference to current decisions.

[0139] The time decay factor used to characterize the time consistency verification evaluation information is obtained in the following way. :

[0140]

[0141] in, The current system timestamp of the vehicle (from the same source as the negotiation message timestamp to avoid clock deviation). For the timestamp of the intended broadcast message, This is the time decay factor, in units of .

[0142] It should be noted that, It is configurable and optimized according to different scenarios. For example, when meeting oncoming traffic on a narrow road, a larger value of λt is used to achieve rapid decay; when parking in AVP mode, a smaller value of λt is used to achieve a smoother decay.

[0143] The intent broadcast message is subjected to scenario consistency evaluation to obtain scenario consistency verification evaluation information. This mainly verifies the semantic matching between the intent declared by the external intelligent agent and the current driving scenario. Only negotiated intents that conform to the semantic constraints of the scenario are allowed to enter the subsequent processing flow, thereby preventing cross-scenario, inapplicable or potentially high-risk negotiated information from affecting the decision-making process of the autonomous driving system.

[0144] In the implementation of this application, the scene consistency factor used to characterize scene consistency verification and evaluation information is obtained in the following manner. :

[0145]

[0146] in, The core intent type for intent broadcast messages, The driving scenario mode currently identified by the vehicle. The set of intents allowed in the current driving scenario. If it is an indicator function, then if the condition is met... This indicates that the scenarios are consistent; if the condition is not met, then... This indicates that the scenarios are inconsistent.

[0147] like If so, it indicates that the scenarios are inconsistent.

[0148] Historical Consistency Evaluation is performed on the intention broadcast message to obtain historical behavior consistency verification evaluation information. This is mainly achieved by statistically analyzing the recent negotiation intentions and behavior patterns of external agents to evaluate the degree of consistency between their current intentions and historical behaviors. As a result, agents with unstable or abnormal behavior are downgraded during the negotiation and fusion process, thereby improving the reliability and robustness of the overall collaborative communication.

[0149] In the implementation of this application, the historical behavior consistency factor used to characterize the historical behavior consistency verification and evaluation information is obtained in the following manner. :

[0150]

[0151] in, K is the historical behavior consistency factor, and K is the historical window length. The quantization value for the currently intended broadcast message. This is the quantization value of the ikth historical meaning graph broadcast message corresponding to the external intelligent agent. This is an absolute value operation, representing the degree of deviation between the current intention and the historical intention.

[0152] It should be noted that the historical window length is configurable. For example, K=5 / 10 means that the most recent K intent messages of the agent are used for statistics.

[0153] The quantization value of the intent broadcast message is, for example, to map the intent type to a numerical value, such as YIELD=0, SHORT_STOP=0.5, GO_FIRST=1, to ensure that the difference can be calculated.

[0154] Among them, if This indicates that the intent is highly consistent with the historical K intents, the agent's behavior is stable, and the reliability is high. If the current intent deviates significantly from the historical K intents, the agent's behavior is erratic / repeatedly changing, resulting in low reliability.

[0155] Furthermore, the consensus prompt information is processed by priority verification and evaluation to obtain priority recommended scenario information, scenario mode verification and evaluation to obtain scenario reference verification and evaluation information, negotiation intent verification and evaluation to obtain intent set and constraint verification and evaluation information, and weak consistency verification and evaluation to obtain weak consistency verification and evaluation information.

[0156] For example, the scenario mode is determined based on the intent broadcast message, the processing priority of L2 for this negotiation session is determined based on the consensus prompt information and priority evaluation is performed, the negotiation intent is evaluated based on the consensus prompt information, and weak consistency evaluation is performed based on the consensus prompt information and the negotiation intent evaluation information.

[0157] In the implementation of this application, after the L3 layer verifies the negotiation session, it generates structured information (NegotiationHintBundle, which is also the core data carrier and the only standardized carrier).

[0158] Furthermore, the agent collaboration layer and the task strategy layer communicate based on the negotiation fusion interface (L3→L2 negotiation fusion interface), and generate a negotiation session structure based on the negotiation fusion interface, which is injected into the orchestration link of the L2 task strategy layer in a structured, verifiable, replayable, rejectable, and degradeable manner.

[0159] In this implementation, the negotiation fusion interface is used to encapsulate and perform security gating on negotiation sessions from external intelligent agents at the protocol level. The negotiation fusion interface is designed based on the following principles: No direct-drive control: The L3 output does not contain any control quantities that can directly drive vehicle actuators (steer angle / throttle pedal opening / brake opening / gear position), only providing "optional negotiation prompts and external risk signals"; Strongly constrained input: The L3 output must satisfy schema verification, validity period constraints, risk gating, and scope verification; otherwise, it is rejected by default; Weak consistency and degradability: The negotiation result is only valid within a finite time window. When a negotiation timeout occurs... In cases of consensus conflict, execution infeasibility, or risk transition, the interface will automatically trigger degradation logic, the negotiation information will become invalid, and the L2 layer will immediately degenerate into a pure single-vehicle autonomous (L2-L0) mode with no collaborative state residue. The evidence chain is traceable: the NegotiationHintBundle output by L3 must carry full-link audit metadata, including trace_id / span_id (aligned with the single-vehicle log system), session_id / epoch (bound to the negotiation state machine), evidence references, and verification results at each stage, to ensure that the entire process of negotiation information from L3 generation and interface transmission to L2 fusion execution is replayable, attributable, and auditable, meeting the problem tracing requirements for engineering implementation.

[0160] That is, in the implementation of this application, the agent collaboration layer and the task strategy layer communicate based on the negotiation fusion interface. The agent collaboration layer generates a negotiation session structure based on the negotiation session and information, including: the agent collaboration layer sends the negotiation session and verification evaluation processing information to the negotiation fusion interface; and the negotiation fusion interface performs protocol-level encapsulation processing on the negotiation session and verification evaluation processing information to generate the negotiation session structure when it determines that the negotiation session meets the first verification evaluation condition based on the verification evaluation processing information.

[0161] The first verification and evaluation criteria include the following: the negotiation session meets the schema verification, the negotiation session is within its validity period, and the risk gating and scope verification of the negotiation session passes.

[0162] For example, the negotiation session output by the L3 layer and the corresponding verification and evaluation processing information must pass four mandatory verifications. If any verification fails, the interface will refuse to receive it by default, and the negotiation information will not enter the L2 decision link, so there will be no impact.

[0163] Specifically, the four-fold verification includes: Schema structure verification: conforming to predefined field specifications, with no missing / illegal fields; Time constraint verification: carrying time constraint fields such as validity_window and deadline_ms, and the time constraint is valid; Risk gating verification: matching the risk level of L0 SafetySummary, and not containing high-risk conflict information; Scope verification: the negotiated scope is consistent with the current driving scenario of the vehicle, and there is no cross-domain information.

[0164] After the verification and evaluation are passed, the L3 negotiation session and the corresponding verification and evaluation processing information are transmitted to the L2 layer in the form of a negotiation session structure (NegotiationHintBundle) based on the negotiation fusion interface, so that the L2 layer can receive the negotiation session structure. The negotiation session structure is a standardized structure information that processes the negotiation session and the corresponding verification and evaluation processing information.

[0165] The original L2 layer decision-making chain used PlanningSnapshot as the core decision input. This interface takes L3 negotiation information and verification evaluation processing information as external negotiation increment input to PlanningSnapshot in the form of negotiation session structure. It enters the L2 policy generation and sub-Agent orchestration chain in parallel with the original input (GoalSpec, WorldSummary, SystemState, SafetySummary, ExecFeedback). The influence weight of the negotiation session structure is dynamically adjusted by the L2 layer according to security constraints and feasibility judgment.

[0166] In the implementation of this application, the output information of the L3 layer carries negotiation prompts, consensus results and risk evidence across vehicles / systems through a unified structure NegotiationHintBundle. The core objective is to converge "external negotiation" into a verifiable and attributable structured input, prevent free text or uncontrollable content from affecting L2 decision-making, and ensure the testability and controllability of the system from the interface level.

[0167] The negotiation session structure is a collection of logical fields (specifically implemented as a JSON / Protobuf file), which includes at least Header (unified envelope / audit metadata), ContextRef (context reference), IntentSet (intent set and constraints), ConsensusResult (weak consistency negotiation result), TrustAndRisk (trustworthiness and risk assessment), and Explainability (explainable fields).

[0168] The Header (unified envelope / audit metadata) carries the protocol version, end-to-end audit identifier, sender / participant information, time constraints, and security verification fields. It is the basic envelope of the structure and the common metadata for all negotiated messages, with fields aligned with the L2 / L0 audit system. Specifically, it includes: protocol version (protocol_version), schema identifier and version (schema_id@schema_version), trace identifier (trace_id / span_id / parent_span_id), sender and participant information (sender_agent_id / peer_set), priority (recommended negotiation prompts are lower than security events, as an example of priority information), L2 converged hard deadline (deadline_ms) (as an example of an effective deadline), and timestamp (monotonic clock + wall clock), optionally carrying payload hash and signature (payload_hash / signature) for integrity verification and authentication.

[0169] ContextRef (an example of scene reference evaluation information) uses a referential design to associate the current decision context of the L2 layer, avoiding the repeated transmission of high-bandwidth data such as PlanningSnapshot and scene mode, while ensuring that L3 negotiation information is strongly bound to the current L2 decision environment to prevent scene mismatch. Specifically, it includes: snapshot_ref: a hash / ID referencing the current L2 PlanningSnapshot to avoid repeated transmission of high-bandwidth information; scene_mode_ref: a reference to the current scene mode (output by the L2 scene agent or rule / model); optionally, it can carry map region / facility references (map_region_ref / facility_ref) to adapt to external system scenarios such as parking lots and access control.

[0170] The IntentSet (intent set and constraints, as an example of intent set and constraint evaluation information) serves to structure and aggregate the intent broadcast / response results of all external agents (S1-S2 phase output). It is the core field for L2 layer to perceive the intent of external agents. Each intent_item corresponds to the declared intent of a participant. Specifically, it includes: multiple intent items (intent_items[]), each intent item aggregates the broadcast / response intent of external agents, intent type (enumeration: yield / YIELD, go first / GO_FIRST, short stop / SHORT_STOP, reverse yield / REVERSE_YIELD, parking space reservation / SLOT_RESERVE, access control opening / GATE_OPEN, etc.), validity window (validity_window: {t_start,t_end} or valid_for_ms, automatically discarded after expiration), external declaration confidence, external declaration risk level (declared_risk_level), and constraint hints (constraints_hint, only includes hints such as recommended safe distance and passage order, without control variables).

[0171] ConsensusResult (a weak consistency negotiation result, serving as an example of weak consistency evaluation information) carries the core output of the S3-S4 phase of the D-A2A negotiation lifecycle, namely the consensus proposal and weak consistency judgment result after multi-agent negotiation. It is the core negotiation information fused by the L2 layer, and all fields are advisory results, which are decided by the L2 layer whether to adopt. Specifically, this includes marking the consensus state (consensus_state: NONE, PARTIAL, REACHED, CONFLICT, EXPIRED), consensus type (consensus_type: RIGHT_OF_WAY, SEQUENCE, RESOURCE_LOCK, such as parking space locking), recommended execution sequence (only a sorting relationship, not a trajectory or control variable), whether it is a conditional commitment (mutual_commitment, such as the other party's commitment to give way but a certain condition must be met), and downgrade policy (downgrade policy, if not reached / conflicted / timeout, the recommended downgrade policy is such as short stop, single-vehicle strategy, requesting manual takeover, etc.).

[0172] TrustAndRisk (credibility and risk assessment) carries the L3 layer's comprehensive credibility score and risk assessment results for the negotiated information. It integrates the intent broadcast credibility modeling mechanism (time / scenario / historical consistency) and the anomaly detection results of protocol-level security protection, providing a quantitative reference for the L2 layer's Accept / Modify / Reject decisions. Specifically, it includes: a comprehensive credibility score (credibility_score, calculated by weighting factors such as time consistency, scenario consistency, historical consistency, and permission scope to obtain the L3 layer's comprehensive credibility score for external negotiated information, serving as an example of credibility assessment information), an adoption risk estimate (risk_estimate, an estimate of the risks that may be introduced by adopting the negotiation prompt, aligned with the L0 risk level, serving as an example of risk assessment information), an anomaly flag set (anomaly_flags, marking issues such as injection, replay, unauthorized access, and inconsistent behavior), and evidence refs (such as a summary of the other party's historical consistency behavior, conflict detection records, message sequence links, etc.).

[0173] The Explainability field carries the reason for the generation of this negotiation prompt and the reference to the negotiation link, realizing the explainability of the negotiation result, adapting to the audit requirements and offline analysis needs of autonomous driving systems, and providing a basis for regression testing / problem localization. Specifically, it includes: reason codes (such as key reason codes such as TIMEOUT_RISK, SCENE_MISMATCH, PEER_UNSTABLE, RESOURCE_CONFLICT, etc.) and audit link reference (audit_trail_ref, pointing to the replayable D-A2A negotiation message chain and key nodes, for use in offline analysis, regression testing, and auditing).

[0174] S300, the task strategy layer, after determining that the negotiation session structure meets the safety constraints and feasibility requirements, generates target driving control strategy indication information based on the negotiation session structure and driving control strategy indication information for use in vehicle driving control.

[0175] In the implementation of this application, the L2 layer (main agent and orchestration kernel) allows the following three types of standardized operations to be performed on the negotiation session structure: Accept, Modify, and Reject, and forms an auditable fusion result.

[0176] In the implementation of this application, when it is determined that the negotiation session structure meets the first triggering condition, it is determined that all the negotiation session structure meets the security constraints and feasibility requirements, the negotiation session structure is accepted, and the target driving control strategy instruction information is generated based on the negotiation session structure and the driving control strategy instruction information.

[0177] The first triggering condition is at least one of the following: the validation and evaluation processing information included in the negotiation session structure is that the schema validation of the negotiation session is passed; the credibility and risk assessment information included in the negotiation session includes an intent credibility score that is greater than a preset first threshold (e.g., 85%); and the credibility and risk assessment information included in the negotiation session includes a risk estimate indicating a low risk level.

[0178] It should be noted that adoption does not mean mandatory execution, but rather that the negotiation session structure is used as an external constraint / bias term in the generation of L2 policies to generate driving policy instruction information for the target vehicle.

[0179] In the implementation of this application, the task strategy layer generates driving control strategy indication information based on the negotiation session structure and task strategy decision information, including: updating the driving control strategy indication information based on the negotiation session structure, determining the target sub-agent in the task strategy layer based on the negotiation session structure, generating a target sub-driving control strategy based on the target sub-agent, and generating target driving control strategy indication information based on the updated driving control strategy indication information and the target sub-driving control strategy.

[0180] For example, the order of each sub-driving control policy in the initial sub-driving control policy set (as an example of driving control policy indication information) included in the task policy layer is updated according to the intent set and constraints included in the negotiation session structure and the weak consistency negotiation result, so as to arrange the sub-driving control policies that satisfy the negotiation session intent first.

[0181] Furthermore, the intent set and constraint information included in the negotiation session structure are injected into the game-type sub-agent (as an example of the target sub-agent) to inject the opponent's commitment and order constraints, so that the game-type sub-agent outputs a target sub-driving control strategy that is more in line with the game's needs. The orchestration kernel included in the task strategy layer adds the target sub-driving control strategy to the updated initial sub-driving control strategy set to generate target driving control strategy indication information.

[0182] It should be noted that when adopting the negotiation session structure at the L2 layer, the attached scope, effective duration set, and rollback trigger conditions must be clearly defined (e.g., L1 execution is not feasible, L0 risk transition).

[0183] Furthermore, in the implementation of this application, when the task strategy layer determines that the negotiation session structure meets the second triggering condition, it determines that part of the negotiation session structure meets the security constraints and feasibility requirements, modifies the negotiation session structure, and generates the target driving control strategy instruction information based on the modified negotiation session structure and the driving control strategy instruction information.

[0184] The second triggering condition is at least one: the credibility score included in the credibility and risk assessment information is greater than or equal to a preset second threshold (e.g., 60%) and less than or equal to a preset first threshold (e.g., 85%), and the risk estimate included in the credibility and risk assessment information indicates a medium risk level.

[0185] For example, when the task strategy layer determines that the negotiation session structure is generally reliable but there are local uncertainties or mismatches, it can make conditional modifications before adopting the modified negotiation session structure, and generate driving control strategy instruction information based on the modified negotiation session structure and task strategy decision information.

[0186] Specifically, the "give way to the other party" prompt has been revised to "stop briefly to detect before proceeding" and L1 feedback on feasibility has been required; the parking space / resource locking prompt has been changed to a priority of candidate targets rather than a mandatory target; and the suggested execution order has been changed to a soft order relationship constraint to support reversal when the risk increases.

[0187] It should be noted that the modification operation must output explicit modification constraints and rollback policies to ensure replayability and regression testing.

[0188] Furthermore, in the implementation of this application, when the task strategy layer determines that the negotiation session structure does not meet the security constraints or feasibility requirements, it rejects the negotiation session structure and uses the driving control strategy instruction information for vehicle driving control.

[0189] The third trigger condition is any of the following: schema verification of the verification and evaluation processing information fails; schema verification field of the verification and evaluation processing information is missing; the protocol version included in the communication metadata is inconsistent with the protocol version supported by the task policy layer; the validity period included in the communication metadata has expired; the validity period of the intent included in the intent set and constraint information has expired; the timestamp is abnormal; the scenario consistency verification result included in the context reference information indicates that the current intent scenario does not belong to the vehicle's allowed scenario set; the intent in the intent list declared by the external intelligent agent included in the intent set and constraint information exhibits unauthorized behavior; the scope corresponding to the intent in the intent list declared by the external intelligent agent included in the intent set and constraint information does not match the scope included in the context reference information; the anomaly marking information included in the credibility and risk assessment results of the weak consistency verification result indicates that there is an anomaly; the credibility score of the intent included in the credibility and risk assessment results is lower than the preset third threshold (e.g., 50%); the risk estimation information included in the credibility and risk assessment results indicates that the risk level is high risk.

[0190] For example, if the validation and evaluation processing information included in the negotiation session structure contains schema validation failure, missing fields, expiration / expiration timeout, scenario mode mismatch, unauthorized permissions, anomaly flag hit, credibility below the threshold, or risk estimation exceeding the limit, then the negotiation session is considered infeasible, the negotiation session structure is rejected, and the system automatically degenerates into a single-vehicle autonomous strategy, that is, determining specific control strategy indication information and vehicle driving control commands based on L2-L1-L0.

[0191] Furthermore, in the implementation of this application, for the accepted and modified negotiation session structure, gating and closed-loop constraint strategies need to be integrated to restrict the negotiation session structure, thereby ensuring that the negotiation session structure meets security constraints and feasibility requirements.

[0192] The task strategy layer obtains security summary information. If the negotiation session structure conflicts with the security summary information, the negotiation session structure is discarded. If the negotiation session structure does not conflict with the security summary information, the layer determines whether the negotiation session structure meets the security constraints and feasibility requirements.

[0193] Security summary information is sent from the security monitoring layer to the task policy layer.

[0194] It should be noted that the conflict determination between the negotiation session structure and the security summary information is achieved through a preset rule set ConflictCheck (NegotiationHintBundle, SafetySummary). This rule set includes at least: whether the scene mode is forbidden; whether the negotiation intent triggers the set of prohibited actions included in the action mask tightening; whether the risk estimate is higher than the current L0 risk limit; and whether the negotiation scope / current referenced scene mode is consistent with the scene gating of the security summary information (SafetySummary).

[0195] For example, if the SafetySummary indicates that the scenario mode or intent policy in the negotiation session structure is a forbidden mode, may have a risk spike, or may trigger action mask tightening, even if L2 adopts the negotiation hint, it must not generate a policy skeleton that violates L0 constraints. When any risk transition event occurs, L2 must immediately trigger rollback / degradation logic to reduce the impact of the negotiation hint to zero or significantly reduce its weight. Only if the negotiation session structure does not conflict with the SafetySummary can it be determined whether the negotiation session structure meets the security constraints and feasibility requirements.

[0196] In another implementation, after accepting or modifying the negotiating agent, the task strategy layer obtains the security summary information. Based on the security summary information, if it is determined that the negotiation session structure conflicts with the security summary information, the negotiation session structure is downgraded to reduce the influence of the negotiation session structure on the driving control strategy instruction information.

[0197] Furthermore, in the implementation of this application, the task strategy determines the execution feedback information obtained by the vehicle driving control according to the target driving control strategy instruction information. If the execution feedback information is determined to be infeasible, the negotiation session structure is downgraded to reduce the influence of the negotiation session structure on the driving control strategy instruction information, or the negotiation session structure is discarded.

[0198] For example, the driving control strategy instruction information (StrategyBundle) formed after L2 adopts / modifies the adoption negotiation session structure must be verified for feasibility through L1 execution feedback. If L2 generates a meta-instruction packet based on the driving control strategy instruction information and sends the meta-instruction packet to L1, after L1 performs vehicle driving control according to the generated vehicle driving control instructions, it reports execution feedback information such as tracking error prediction exceeding the standard, actuator saturation risk, planning solution failure or infeasibility feedback, and immediately triggers the L2 rollback strategy, indicating that L2 automatically reduces its weight or cancels the corresponding negotiation prompt.

[0199] Thus, the negotiation session structure is further constrained based on L0 hard constraint gating and L1 feasibility closed-loop gating, so that the driving control strategy indication information included in the final meta-instruction package generated by L2 is information that satisfies the constraints of L0 and the feasibility of L1.

[0200] In this implementation, the L2 layer's handling of negotiation prompts must strictly adhere to real-time and deterministic requirements to ensure stable system operation. Real-time budget constraints: L3 negotiation session structures can only participate in fusion within a time limit of deadline_ms; if the timeout occurs, they are directly considered invalid and do not affect the normal L2 decision-making process. Deterministic output: The same PlanningSnapshot and the same version of NegotiationHintBundle must output consistent fusion decision records to facilitate system reproduction and functional certification. Timeout degradation mechanism: When L3 negotiation information is missing, conflicting, or unavailable, the system automatically degrades to the L2 single-vehicle strategy (rule-based strategy, conservative strategy, or maintaining the current state). If necessary, L2 / L0 decides to trigger a short stop or request manual takeover to ensure overall robustness.

[0201] Furthermore, based on the vehicle driving control method of this application, the L2 layer generates target driving control strategy indication information, and then obtains the meta-instruction packet. The meta-instruction packet is then sent to the real-time control layer. The real-time control layer generates decision information based on the safety constraint indication information sent by the safety monitoring layer, the meta-instruction packet sent by the task strategy layer, and the control instructions corresponding to the vehicle in the previous cycle. The vehicle driving control instruction is then used to control the vehicle driving.

[0202] like Figure 4As shown, the vehicle driving control method of this application is also a vehicle driving control method for all external intelligent agents that require negotiation. It includes: a task strategy layer determining the task strategy decision information corresponding to the vehicle; generating driving control strategy instruction information to guide vehicle driving based on the task strategy decision information; an intelligent agent collaboration layer, when determining that the task strategy layer needs to introduce external intelligent agent capabilities, establishing a negotiation session with at least one external intelligent agent based on a preset intelligent agent communication protocol; performing verification and evaluation processing on the negotiation session to obtain verification and evaluation processing information; and generating a negotiation session structure based on the negotiation session and the verification and evaluation processing information when the verification and evaluation processing information indicates that the verification and evaluation has passed, sending the negotiation session structure to the task strategy layer; the task strategy layer receiving / modifying / rejecting the negotiation session structure; generating target driving control strategy instruction information based on the negotiation session structure and the driving control strategy instruction information for vehicle driving control when the negotiation session structure is rejected; and performing vehicle driving control based on the driving control strategy instruction information when the negotiation session structure is rejected.

[0203] Next, the vehicle driving control system of this application will be described in a specific application scenario.

[0204] (I) Multi-vehicle yielding negotiation scenario: This scenario applies to situations involving right-of-way disputes and conflicts, such as narrow two-way single-lane roads and turning / passing in underground parking garages. In such scenarios, the driving paths of multiple vehicles intersect and there is a lack of fixed traffic signs or a common decision-making node. Traditional single-vehicle autonomous decision-making is prone to problems such as repeated probing, sudden braking, and stalemates. The core requirement of this scenario is to reach a consensus on yielding / priority through multi-vehicle intention negotiation, reduce ineffective operations, improve traffic efficiency, and ensure driving safety without bypassing the single-vehicle safety closed loop.

[0205] In one implementation, the specific process of handling multi-vehicle yielding negotiation based on the lifecycle control mechanism includes: the scene intelligent agent of the vehicle enters and detects the surrounding effective cooperative intelligent agents to initialize the negotiation session; the initiating vehicle publishes an intent broadcast message; the participating vehicles return intent response messages to conduct condition negotiation; the negotiation engine included in the intelligent agent negotiation layer aggregates multiple rounds of intent interactions into a standardized consensus proposal and completes verification and evaluation processing such as weak consistency judgment; the task strategy layer executes a standardized decision of accepting, modifying or rejecting the consensus prompt information (i.e., the negotiation session structure); the negotiation terminates and returns to the single-vehicle autonomous closed loop after the passage is completed or the abnormal fallback condition is triggered. For example, the scenario sub-agent in the vehicle task strategy layer L2 identifies negotiable scenarios such as entering a narrow road / parking garage and detecting surrounding effective cooperating agents to initialize a negotiation session (i.e., stage S0). The initiating vehicle (entering the narrow road / parking garage first) broadcasts an intent message (i.e., stage S1). After receiving the intent broadcast, the participating vehicles return an intent response message to negotiate conditions, such as "I will SHORT_STOP (300ms) and you go first" (i.e., stage S2). The negotiation engine included in the agent negotiation layer aggregates multiple rounds of intent interactions into a standardized yield consensus proposal (i.e., stage S3) and performs weak consistency judgment and other verification and evaluation processing based on the consensus proposal (i.e., stage S4). The task strategy layer L2 performs standardized decisions such as accept, modify, and reject on the consensus prompt information (i.e., negotiation session structure) (i.e., stage S5). The negotiation terminates and returns to the single-vehicle autonomous closed loop after passing through or triggering an abnormal fallback condition, such as the vehicle completing the passing through according to the consensus or returning to single-vehicle autonomy in an abnormal state (i.e., stage S6).

[0206] In this way, multiple vehicles exchange structured intentions and form verifiable consensus prompts through the D-A2A protocol, replacing the "repeated probing" under the traditional single-vehicle autonomy, which greatly improves traffic efficiency. Furthermore, through dual gating verification of the safety monitoring layer and the real-time control layer, the uncontrollable safety risks caused by the introduction of collaboration are avoided, and orderly negotiation and safe passage are achieved for vehicles meeting on narrow roads / garages.

[0207] (II) Adversarial Driving Simulation Data Generation Scenario (Core Scenario for Model Training and Extreme Scenario Validation): Addressing the pain points of "low frequency of occurrence, difficulty in covering human rules, and difficulty in reproducing human data" in high-value adversarial scenarios such as overtaking, standoffs, and misjudgment of intent in the real world, multiple autonomous agents with complete L2-L1-L0 stacks are instantiated in the simulation environment. Real intention interaction driven by non-scripts is realized through the D-A2A protocol, allowing adversarial behaviors to emerge naturally. At the same time, labeled data with interpretable labels is automatically generated to adapt to reinforcement learning training, policy regression testing, and extreme scenario validation.

[0208] Specifically, on the simulation side, multiple autonomous agents run in parallel. Each vehicle is instantiated to complete the L2-L1-L0 architecture. Each external agent has an independent sub-Agent repository, behavioral preferences (aggressive / conservative / courteous), risk thresholds, and constraint parameters.

[0209] D-A2A, acting as an "adversarial behavior generator," enables multiple agents to interact with each other through the D-A2A protocol based on their true intentions, rather than being script-driven. Adversarial behaviors naturally emerge, such as: both parties predicting the other will give way → stalemate, one party with high uncertainty → short stop for detection, and multiple vehicles competing for the same right of way.

[0210] Furthermore, through A2A trace and decision-making links, it automatically generates behavioral adversarial level labels, failure reasons (intent conflict / overly tight constraints / infeasibility of execution), L0 intervention counts, and risk transition nodes.

[0211] For example, taking the "intersection stalemate" adversarial scenario based on the lifecycle control mechanism as an example, firstly, a scenario of an intersection without traffic lights is loaded into the simulation environment, and at least two autonomous agents (one aggressive and one conservative) are instantiated. The scenario agent is identified as a negotiable scenario, and the aggressive agent publishes an Intent. Broadcast, intent_type=GO_FIRST (forced preemption), bound to validity_window=2000ms, declared_risk_level=L3 (high risk); a conservative agent publishes intent_type=YIELD (default yielding), declared_risk_level=L1 (low risk). After receiving the conservative agent's YIELD intent, the aggressive agent returns ACK; however, the conservative agent detects the aggressive agent's high-risk preemption and updates its intent to GO_FIRST (refuse to yield), rebroadcasts in the new epoch, triggering multiple rounds of game theory. The multi-round adversarial intent interaction is transformed into structured proposals, generating candidate solutions even in the event of conflict: Proposal 1: Aggressive agent goes first, conservative agent stops briefly (commitment_type=HARD-LIMITED); Proposal 2: Both parties stop briefly for 500ms and then alternate passage (commitment_type=CONDITIONAL); At the same time, the proposal risk_estimate=L3 (high risk) is marked because of the preemption conflict. The radical agent accepts proposal 1, and the conservative agent accepts proposal 2. The two cannot reconcile, so consensus_state=CONFLICT (conflict). Furthermore, because consensus_state=CONFLICT+TIMEOUT, this scenario does not enter the S5 execution stage, but directly jumps from S4 to S6 (ABORT). If a partial consensus is reached, the L2 layer executes the Modify decision, corrects the proposal, and observes. If L1 / L0 detects that execution is not feasible, it immediately rolls back.

[0212] Thus, without the need for manual rule design, high-value adversarial driving data can be generated in batches through multi-agent D-A2A protocol interaction, solving the problem of real-world data scarcity; the data comes with interpretable labels: the annotation information is deeply bound to the decision-making link, which is suitable for reinforcement learning model training (optimizing game strategy), policy regression testing (verifying robustness), and extreme scenario verification (covering edge cases); it flexibly adapts to multiple adversarial scenarios: by adjusting the agent's behavioral preferences and negotiation parameters, various adversarial scenarios such as cutting in line, stalemate, intention misjudgment, and multiple vehicles competing for lanes can be generated to adapt to different training needs.

[0213] (III) AVP valet parking and smart home collaboration (i.e., the core scenario of vehicle-facility cross-intelligent agent collaboration). This scenario is applicable to vehicle-facility collaboration scenarios such as smart garages, community access control, and home charging piles. Autonomous vehicles interact with external intelligent agents such as garages, access control, and charging systems. The core requirement is to achieve unmanned collaboration in parking space allocation, entry and exit order coordination, and autonomous timely charging, replacing traditional manual operation and improving the intelligence and convenience of AVP valet parking. The core features are two-way negotiation between vehicle and facility, resource (parking space / charging pile) locking, and low-risk scenarios.

[0214] In the implementation method of this application, the life cycle control mechanism can realize unmanned vehicle-facility collaboration. For example, the vehicle and the smart garage and charging pile can realize fully automatic parking space allocation, path planning and charging start-up through the D-A2A protocol without human intervention, thus improving the intelligent experience of AVP valet parking.

[0215] Furthermore, the decentralized intelligent agent collaborative communication architecture of this application can be applied to any scenario such as V2V, V2I (Infrastructure), and V2N (Network).

[0216] For example, consider any of the following scenarios:

[0217] (1) Temporary traffic organization and construction area collaboration scenarios: For example, nighttime road construction, temporary road closures, and dynamic changes in cones and diversion areas. Vehicles and external intelligent agents such as construction area sensing equipment and temporary roadside control units negotiate and interact. The negotiation content includes the passable width, one-way passage time window, temporary passage rules and validity window, etc. In this type of "temporary rules ≠ fixed map" scenario, strategy stability and risk isolation are achieved through negotiation prompts that are time-sensitive, can be rejected, and can be downgraded.

[0218] (2) Emergency vehicle collaboration scenario: For example, in the scenario of temporary passage requests of emergency vehicles such as ambulances and fire trucks, the vehicle negotiates and interacts with the emergency vehicle intelligent agent or the city emergency dispatch system. The negotiation content includes the emergency passage intention, yielding request, yielding scope and validity period, etc. At the same time, through permission and scope verification, credibility assessment and anomaly detection, the forged emergency identity or unauthorized requests are intercepted to ensure that "negotiation ≠ forced command".

[0219] (3) High-speed entrance / ramp merging coordination scenario: For example, ramp congestion, multiple vehicles vying for lane change and merging game scenario, vehicles negotiate and interact with other vehicle intelligent agents or ramp management units. The negotiation content includes merging timing, speed window, gap constraint and consensus validity period, etc. The negotiation result forms a prompt in a weak consistency manner and can be revoked / rolled back when execution is infeasible or risky transition.

[0220] (4) Collaborative scenarios of automated parking garages / mechanical parking spaces: For example, in scenarios involving the handling of mechanical parking spaces and docking with lifting platforms, the vehicle and mechanical parking space control system negotiate and interact. The negotiation content includes available time windows, vehicle size / weight constraints, allowed entry and exit sequences and locking conditions, etc. The negotiation prompts must be verified for feasibility before they can be adopted, so as to avoid the direct injection of external facility strategies, which may cause actions to be unreachable or safety risks.

[0221] (5) Temporary parking rights and loading / unloading resources game scenario: For example, the scenario of competing for parking rights in the loading / unloading area and temporary parking area of ​​a commercial street. The vehicle negotiates and interacts with the commercial area management system and other vehicle intelligent agents. The negotiation content includes parking duration, transfer order, occupation range, release conditions and validity period, etc. In this type of limited resource + time game scenario, the negotiation prompt can be modified to a conservative strategy and supports timeout failure.

[0222] Furthermore, traditional V2X / V2V / C-V2X communication architectures are mainly used in vehicle-to-vehicle and vehicle-to-roadside communication fields. They are located in the communication and information perception layer, belonging to the underlying architecture. The communication objects are mainly physical entities such as vehicles, roadside units, and traffic lights. The focus is on "whether the information is delivered". The information exchanged is mainly status data (such as location, speed, acceleration, traffic light status, etc.). It cannot understand the driving intention, only plays a transmission role, and does not participate in driving decision-making. It only acts as an information source for transmission. The real-time requirement is strong real-time, millisecond level, and the consistency requirement is synchronous assumption consistency. The failure handling mechanism is that communication failure means information loss. It does not have the ability to make safety decisions and does not provide decision explanations. It is mainly used for real communication. Even though V2X, for example, can be simulated in the simulation environment because it focuses on state message transmission and perception enhancement, its protocol semantics and mechanisms do not directly cover multi-round intention negotiation, revocable commitment, and auditable negotiation closed loop. In addition, traditional communication architectures need to customize specific interfaces to receive communication requirements from external systems (such as garages). If functional expansion is required, it is mainly based on cross-extension of communication fields.

[0223] The vehicle driving control system provided in this application is a D-A2A multi-agent cooperative architecture. Compared with traditional V2X / V2V / C-V2X communication architectures, it is an agent cooperative mechanism oriented towards autonomous driving decision-making. Located at the decision and strategy layer, it belongs to a high-level architecture. The communication can correspond to agents (Master Agents), including in-vehicle sub-agents, other vehicle decision agents, and external system agents. The focus is on "whether it should be done, who should do it first, and how to do it." The exchanged information includes driving intentions, strategy fragments, risk assessments, constraint prompts, and rollback suggestions. It can understand driving intentions, explicitly model and exchange executable intentions, and directly participate in multi-agent decision-making and negotiation. The real-time requirement is not strong real-time (hundreds of milliseconds), and it supports expiration and discarding. The consistency requirement is not strong consistency, and it supports rollback and degradation. Its failure handling mechanism is that the policy can be revoked, replaced, and rolled back. It also works in collaboration with the L0 safety loop and has risk gating. Each policy and negotiation result has an interpretable chain of evidence. It naturally supports multi-agent adversarial simulation and data generation and can be applied to simulation scenarios. External systems can directly access it as an agent, and new capabilities can be hot-swapped and extended in the form of sub-agents.

[0224] Therefore, the vehicle driving control method and system provided in this application break through the limitations of traditional autonomous driving's "single-vehicle self-consistency," achieving decentralized collective intelligent collaboration between vehicles and between vehicles and external facilities, adapting to complex scenarios such as multi-vehicle interaction and vehicle-to-thing interconnection. The entire process is structured, verifiable, and traceable, with all designs centered around the real-time decision-making needs of the vehicle, featuring lightweight design, low latency, high compatibility, and suitability for mass production. In addition to the three core scenarios mentioned above, the D-A2A protocol can quickly adapt to scenarios such as high-speed platooning, intersection without traffic signals, and unmanned vehicle scheduling in industrial parks, requiring only minor adjustments to the intent type and negotiation parameters, exhibiting extremely high scalability. It not only enables scenario-based collaboration but also generates high-value labeled data in simulation scenarios, feeding back into the training and testing of autonomous driving models, forming a closed loop of "collaboration-data-optimization."

[0225] This application also provides a vehicle, including a vehicle driving control system for executing a vehicle driving control method.

[0226] This application also provides a chip for executing instructions, which is used to execute the vehicle driving control method described in the above embodiments.

[0227] This application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed on the processor of a computer device, the processor of the computer device executes the technical solution of the vehicle driving control method described in the above embodiments.

[0228] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solution of the vehicle driving control method in the above embodiments.

[0229] It should be noted that, in addition to the specific embodiments described above, those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. Although the description of this application is presented in conjunction with preferred embodiments, this does not mean that the features of this application are limited to this implementation. On the contrary, the purpose of describing the application in conjunction with the implementation is to cover other options or modifications that may be derived from this application. To provide a thorough understanding of this application, many specific details are included in the above description, and this application may also be implemented without using these details. Furthermore, to avoid confusion or obscuring the focus of this application, some specific details will be omitted in the description. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other.

[0230] It should be noted that in this specification, similar reference numerals and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0231] It should be noted that the terms "first" and "second" are used only to distinguish descriptions and should not be interpreted as indicating or implying relative importance.

[0232] It should be noted that some structural or methodological features may be shown in the accompanying drawings in a specific arrangement and / or order. However, it should be understood that such a specific arrangement and / or order may not be necessary. Rather, in some embodiments, these features may be arranged in a manner and / or order different from that shown in the illustrative drawings. Furthermore, including structural or methodological features in a particular figure does not imply that such features are required in all embodiments, and in some embodiments, these features may be omitted or may be combined with other features.

[0233] Although this application has been illustrated and described with reference to certain preferred embodiments, those skilled in the art should understand that the above description is a further detailed explanation of the application in conjunction with specific implementations, and should not be construed as limiting the specific implementation of the application to these descriptions. Those skilled in the art can make various changes in form and detail, including some simple deductions or substitutions, without departing from the spirit and scope of this application.

Claims

1. A vehicle driving control method, characterized in that, Applied to a vehicle, the vehicle includes a vehicle driving control system for implementing vehicle driving control, the vehicle driving control system including an agent coordination layer and a task strategy layer, the method including: The task strategy layer determines the task strategy decision information corresponding to the vehicle, and generates driving control strategy instruction information to guide the vehicle's driving based on the task strategy decision information; When the intelligent agent collaboration layer determines that the task strategy layer needs to introduce external intelligent agent capabilities, it establishes a negotiation session with at least one external intelligent agent based on a preset intelligent agent communication protocol, performs verification and evaluation processing on the negotiation session, obtains verification and evaluation processing information, and when it is determined that the verification and evaluation processing information indicates that the verification and evaluation has passed, it generates a negotiation session structure based on the negotiation session and the verification and evaluation processing information, and sends the negotiation session structure to the task strategy layer. The external intelligent agent is an external computing node or external device that has communication interaction and collaborative decision-making requirements with the vehicle driving control system. When the task strategy layer determines that the negotiation session structure meets the safety constraints and feasibility requirements, it generates target driving control strategy indication information based on the negotiation session structure and the driving control strategy indication information for vehicle driving control. This generation of target driving control strategy indication information, when the negotiation session structure meets the safety constraints and feasibility requirements, includes: when the negotiation session structure meets a first triggering condition, determining that the negotiation session structure fully meets the safety constraints and feasibility requirements, accepting the negotiation session structure, and generating the target driving control strategy indication information based on the negotiation session structure and the driving control strategy indication information; when the negotiation session structure meets the ... and when the negotiation session structure meets the first triggering condition, determining that the negotiation session structure fully meets the safety constraints and feasibility requirements, accepting the negotiation session structure, and generating the target driving control strategy indication information based on the negotiation session structure and the driving control strategy indication information. When the negotiation session structure meets the second triggering condition, it is determined that the negotiation session structure partially meets the security constraints and feasibility requirements. The negotiation session structure is modified, and the target driving control strategy indication information is generated based on the modified negotiation session structure and the driving control strategy indication information. Furthermore, generating the target driving control strategy indication information based on the negotiation session structure and the driving control strategy indication information includes: updating the driving control strategy indication information based on the negotiation session structure, determining the target sub-agent in the task strategy layer based on the negotiation session structure, generating a target sub-driving control strategy based on the target sub-agent, and generating the target driving control strategy indication information based on the updated driving control strategy indication information and the target sub-driving control strategy.

2. The vehicle driving control method according to claim 1, characterized in that, The negotiation session is a session message generated based on intent broadcast messages, intent response messages, and consensus prompt messages during multiple communication sessions. The verification and evaluation process includes at least one of the following: Semantic security verification and evaluation processing; Anomaly and injection verification and evaluation handling; Permission and scope verification and evaluation processing; Weak consistency verification evaluation and processing; Time consistency verification and evaluation processing; Credibility verification and evaluation process.

3. The vehicle driving control method according to claim 2, characterized in that, The agent collaboration layer and the task strategy layer communicate based on a negotiation fusion interface. The agent collaboration layer generates a negotiation session structure based on the negotiation session and the verification and evaluation processing information, including: The intelligent agent collaboration layer sends the negotiation session and the verification and evaluation processing information to the negotiation fusion interface; When the negotiation fusion interface determines that the negotiation session meets the first verification and evaluation conditions based on the verification and evaluation processing information, it performs protocol-level encapsulation processing on the negotiation session and the verification and evaluation processing information to generate the negotiation session structure. The first verification and evaluation conditions include the following conditions: the negotiation session meets the schema verification, the negotiation session is within the validity period, and the risk gating and scope verification of the negotiation session passes.

4. The vehicle driving control method according to claim 3, characterized in that, The method further includes: When the task strategy layer determines that the negotiation session structure meets the third triggering condition, it determines that the negotiation session structure does not meet the security constraints or feasibility requirements, rejects the negotiation session structure, and uses the driving control strategy instruction information for vehicle driving control.

5. The vehicle driving control method according to claim 4, characterized in that, The method further includes: The task policy layer obtains security digest information. Based on the security digest information, if it determines that the negotiation session structure conflicts with the security digest information, it discards the negotiation session structure. If it determines that the negotiation session structure does not conflict with the security digest information, it determines whether the negotiation session structure meets security constraints and feasibility requirements; and / or The task strategy layer determines the execution feedback information obtained by the vehicle driving control according to the target driving control strategy instruction information. If the execution feedback information indicates that execution is not feasible, the negotiation session structure is downgraded or discarded.

6. The vehicle driving control method according to claim 5, characterized in that, The preset agent communication protocol is a decentralized A2A communication protocol. The agent collaboration layer and the external agent negotiate and communicate based on this decentralized A2A protocol. The agent collaboration layer and the task strategy layer communicate within the vehicle based on this A2A protocol. The decentralized A2A communication protocol includes a negotiation lifecycle control mechanism. The agent collaboration layer determines the negotiation session with the external agent, performs verification and evaluation processing on the negotiation session, and obtains verification and evaluation processing information, including: The intelligent agent collaboration layer establishes a negotiation session with the external intelligent agent based on the negotiation lifecycle control mechanism, and performs verification and evaluation processing on the negotiation session to obtain verification and evaluation processing information.

7. A vehicle driving control system, characterized in that, The vehicle driving control system is applied to the vehicle and includes an intelligent agent coordination layer and a task strategy layer, wherein... The task strategy layer is used to determine the task strategy decision information corresponding to the vehicle, and generate driving control strategy instruction information to guide the vehicle's driving based on the task strategy decision information; The agent collaboration layer is used to establish a negotiation session with at least one external agent based on a preset agent communication protocol when it is determined that the task strategy layer needs to introduce external agent capabilities. The negotiation session is then verified and evaluated to obtain verification and evaluation processing information. If the verification and evaluation processing information indicates that the verification and evaluation has passed, a negotiation session structure is generated based on the negotiation session and the verification and evaluation processing information. The negotiation session structure is then sent to the task strategy layer. The external agent is an external computing node or external device that has communication interaction and collaborative decision-making requirements with the vehicle driving control system. The task strategy layer is used to generate target driving control strategy indication information for vehicle driving control, based on the negotiation session structure and the driving control strategy indication information, when it is determined that the negotiation session structure meets the safety constraints and feasibility requirements. This generation of target driving control strategy indication information, when it is determined that the negotiation session structure meets the safety constraints and feasibility requirements, includes: when it is determined that the negotiation session structure meets a first triggering condition, determining that the negotiation session structure fully meets the safety constraints and feasibility requirements, accepting the negotiation session structure, and generating the target driving control strategy indication information based on the negotiation session structure and the driving control strategy indication information; when it is determined that the negotiation session structure meets the ... When the session structure meets the second triggering condition, it is determined that the negotiation session structure partially meets the security constraints and feasibility requirements. The negotiation session structure is then modified. Based on the modified negotiation session structure and the driving control strategy indication information, the target driving control strategy indication information is generated. Furthermore, generating the target driving control strategy indication information based on the negotiation session structure and the driving control strategy indication information includes: updating the driving control strategy indication information based on the negotiation session structure; determining the target sub-agent in the task strategy layer based on the negotiation session structure; generating a target sub-driving control strategy based on the target sub-agent; and generating the target driving control strategy indication information based on the updated driving control strategy indication information and the target sub-driving control strategy.

8. A vehicle, characterized in that, The vehicle includes the vehicle driving control system as described in claim 7 to perform the vehicle driving control method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Vehicle and road cloud integrated traffic control method for automatic driving lane changing

    CN120186186A

  • Dynamic path planning method and system in intelligent traffic system

    CN120252763A