Method and system for functional safety and intended function assurance of an in-vehicle bus

By collecting the vehicle controller's operating status signals and environmental perception data, a coordinated and consistent safety response strategy is generated. This strategy is then executed collaboratively by the safety island hardware and the main computing unit, resolving the conflicting response strategies of the vehicle controller in the event of hardware failure and perception anomalies. This improves the system's robustness and security, ensuring safe operation under various abnormal conditions.

CN121697658BActive Publication Date: 2026-05-12NINGBO HAISHU XUELIMAN ELECTRONIC CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NINGBO HAISHU XUELIMAN ELECTRONIC CO LTD
Filing Date
2026-02-13
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

When hardware failures or perceived anomalies occur in the vehicle controller, the functional safety mechanisms lack coordination with the expected functional safety mechanisms, leading to conflicting response strategies and incomplete coverage, thus reducing the overall safety of the system.

Method used

By collecting the operating status signals of the main computing unit and environmental perception data, fault diagnosis and risk assessment are performed to generate a coordinated and consistent safety response strategy. The safety island hardware works in conjunction with the main computing unit to form a complete safety closed loop, achieving dual protection of functional safety and expected functional safety.

Benefits of technology

It significantly improves the system robustness and overall safety of the vehicle controller in complex environments, ensuring safe operation in the event of hardware failure and perception anomalies, including seamless control transfer under severe failure and progressive function degradation under non-severe failure, thereby achieving system resilience and improved user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121697658B_ABST
    Figure CN121697658B_ABST
Patent Text Reader

Abstract

The application relates to a function safety and expected function guarantee method and system of a vehicle-mounted bus, relates to intelligent driving safety technology, and comprises the following steps: collecting an operation state signal of a main computing unit; performing fault diagnosis based on the operation state signal to obtain a fault level; determining a safety response strategy according to the fault level; collecting environment perception data and a credibility evaluation value; performing expected function safety risk evaluation by combining the environment perception data and the credibility evaluation value to obtain a risk level; matching a corresponding expected function safety processing strategy according to the risk level; and controlling a safety island hardware and the main computing unit to cooperatively execute the safety response strategy and the expected function safety processing strategy, so that dual guarantee of function safety and expected function safety is realized. The application has the effect of improving the overall safety of a system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent driving safety technology, and in particular to a method and system for ensuring the functional safety and expected functions of an in-vehicle bus. Background Technology

[0002] A vehicle controller is a core onboard controller that integrates the functions of multiple electronic control units in a vehicle, achieving integrated computing, communication, and control.

[0003] Currently, vehicle controllers typically employ independent safety island hardware and multiple monitoring mechanisms, enabling them to quickly take over the vehicle's underlying control when a main controller malfunction is detected, thus implementing basic safety functions such as braking and steering. Simultaneously, through multi-sensor fusion algorithms and reliability assessments, anomalies in sensor data from cameras, radar, and other sources can be identified and filtered, reducing the risk of misjudgments.

[0004] However, when the system experiences both hardware failure (such as main computing unit crash) and sensing anomalies (such as sensor failure due to environmental factors), the functional safety mechanism lacks coordination with the expected functional safety mechanism, leading to conflicting or incomplete response strategies, which reduces the overall security of the system and needs to be improved. Summary of the Invention

[0005] To improve the overall safety of the system, this invention provides a method and system for ensuring the functional safety and expected functionality of an on-board bus.

[0006] In a first aspect, the present invention provides a method for ensuring the functional safety and expected functionality of an in-vehicle bus, employing the following technical solution:

[0007] A method for ensuring the functional safety and intended functionality of an onboard bus includes:

[0008] Collect the operating status signals of the main computing unit;

[0009] Fault diagnosis is performed based on operating status signals to determine the fault level;

[0010] Determine the safety response strategy based on the fault level;

[0011] Collect environmental perception data and credibility assessment values;

[0012] By combining environmental perception data and credibility assessment values, an expected functional safety risk assessment is conducted to obtain the risk level.

[0013] Match the expected functional safety handling strategy according to the risk level;

[0014] The control security island hardware and the main computing unit work together to execute security response strategies and expected functional safety processing strategies to achieve dual protection of functional safety and expected functional safety.

[0015] By adopting the above technical solution, and through parallel processing of operating status signals and environmental perception data, synchronous monitoring and diagnosis of hardware faults and perceived risks are achieved. Based on the dynamic matching of fault level and risk level, a coordinated safety response strategy and expected functional safety handling strategy are generated. Finally, through the collaborative execution of the safety island hardware and the main computing unit, a complete safety closed loop from fault handling to risk response is formed. This effectively solves the problem of response conflict and coverage blind spots caused by the isolated operation of functional safety and expected functional safety mechanisms in traditional solutions, and significantly improves the system robustness and overall safety of the vehicle controller in complex operating environments.

[0016] Optionally, a method for determining the fault level may also be included:

[0017] Abnormal characteristic parameters are obtained based on operating status signals;

[0018] The number of abnormal features is determined based on the abnormal feature parameters;

[0019] The system health score is calculated by the number of abnormal features.

[0020] The fault level is determined based on the system health score and a preset fault level mapping rule.

[0021] By adopting the above technical solution, multi-dimensional abnormal feature parameters are extracted from the operating status signal to establish a system health score model based on the number of features. Then, the fault level is automatically classified through fault level mapping rules. This can accurately identify the gradual process of system health status change, provide accurate decision-making basis for subsequent graded safety response, and effectively improve the accuracy of fault diagnosis and system fault tolerance.

[0022] Optionally, the security response strategy includes:

[0023] When the fault level is the preset severe fault level, the independent safety island hardware takes over the vehicle's underlying control and collects the vehicle's current operating status and current environmental information.

[0024] Determine the least risk path based on the vehicle's current operating status and current environmental information;

[0025] The control safety island hardware performs basic braking and steering operations, guides the vehicle to travel along the path of least risk, and collects vehicle position and attitude information.

[0026] Determine whether a vehicle is in a safe parking state by using vehicle location information, vehicle posture information, and current environmental information;

[0027] When the vehicle is in a safe parking state, the system will trigger a safety lock and send a remote alarm message.

[0028] By adopting the above technical solution, when the system determines a serious fault, the independent takeover of the safety island hardware ensures a seamless transfer of control. The minimum risk path generated based on multi-source information fusion guarantees the rationality of the vehicle's risk avoidance process, while continuous status monitoring and safe stopping judgment realize closed-loop management of the risk avoidance process. Furthermore, it not only avoids the risk of execution failure caused by main system failure through direct control of the underlying hardware, but also ensures the optimization of the risk avoidance strategy through the dynamic fusion of environmental perception and vehicle status. Finally, with the help of system safety locking and remote alarms, it completes the entire process of protection from the occurrence of the fault to the maintenance of a safe state, significantly improving the system's survivability in serious fault scenarios.

[0029] Optionally, the security response strategy further includes:

[0030] When the fault level is not the preset severe fault level, a function degradation scheme is matched from the preset degradation strategy library according to the fault level.

[0031] Determine the scope of restricted functions based on the function degradation scheme;

[0032] The redundant computing unit takes over the computing tasks of the main computing unit, performs corresponding functional limitation operations according to the limited functional range, prompts the driver to take over, and collects the driver's status information at the same time.

[0033] Assess takeover readiness based on driver status information;

[0034] The alarm level and prompting method are determined based on the takeover readiness level, and prompts are given based on the alarm level and prompting method. When effective driver takeover is detected, the autonomous driving function is gradually disengaged.

[0035] By adopting the above technical solutions, the precise matching of fault levels and function degradation schemes ensures the rational allocation of system resources and the accurate implementation of function restrictions; the task takeover of redundant computing units ensures the continuous operation of the system's core functions; the alarm and prompt mechanism based on dynamic driver status assessment effectively improves the efficiency and safety of human-machine interaction; and finally, the gradual function exit strategy ensures the smooth and reliable handover of control, thereby maximizing the maintenance of vehicle operation capabilities, creating favorable conditions for driver takeover, and significantly improving the system's resilience and user experience under non-serious faults.

[0036] Optionally, the expected functional safety processing strategy includes:

[0037] When the risk level is high, the preset fault tolerance and compensation mechanism is activated to output uncertainty warnings to the human-computer interaction interface and reduce the system function confidence level.

[0038] Collect historical environmental data and real-time data from multiple sensors;

[0039] Based on historical environmental data and real-time data from multiple sensors, a preset compensation algorithm is used to correct the environmental perception data.

[0040] A high-confidence environmental model is generated based on the revised environmental perception data, and the risk level is reassessed based on the high-confidence environmental model.

[0041] The decision-making process will be based on the reassessed risk level to determine the execution status of the target autonomous driving function.

[0042] By adopting the above technical solutions, when the system identifies high risks, it achieves the isolation and intelligent repair of perceived data through fault tolerance and compensation mechanisms. The fusion and compensation of historical environmental data and real-time data from multiple sensors effectively improves the reliability of environmental perception. A high-confidence environmental model generated based on the corrected data provides an accurate basis for risk reassessment. Finally, through dynamic decision-making based on the functional execution state, the system achieves smooth degradation and safe recovery under abnormal perception conditions, ensuring the continuous safe operation of autonomous driving functions in uncertain scenarios.

[0043] Optional, intelligent compensation methods are also included:

[0044] A normal data feature library is generated based on historical environmental data, and historical normal data is retrieved based on the normal data feature library.

[0045] Based on a normal data feature library and real-time data from multiple sensors, abnormal sensing data is identified.

[0046] Data compensation parameters are generated based on historical normal data and real-time data from multiple sensors.

[0047] The abnormal perception data is corrected based on the data compensation parameters, thereby completing the correction of the environmental perception data.

[0048] By adopting the above technical solutions and establishing a historical normal data feature library, a reliable benchmark reference is provided for anomaly identification. Cross-validation using real-time data from multiple sensors enables accurate identification and location of abnormal perception data. Data compensation parameters generated based on historical normal data and real-time data ensure the scientific nature and adaptability of perception data correction. This not only effectively restores the environmental perception capability caused by sensor anomalies, but also improves the system's adaptability to complex environmental changes through continuous feature library updates and parameter optimization, providing a more reliable environmental cognition guarantee for autonomous driving decision-making.

[0049] Optional, also includes:

[0050] The camera's operational status is determined based on a confidence level assessment.

[0051] When the camera is in an obstructed state, it collects obstructed image information.

[0052] Feature extraction of the occluded region is performed from the occluded image information to obtain the specific occlusion status;

[0053] Identify specific occlusion areas based on occlusion image information and preset occlusion features;

[0054] When the specific occlusion state is the preset close-range coverage occlusion, the blowing cleaning parameters are determined according to the specific occlusion area, and the camera lens is cleaned in a targeted manner according to the blowing cleaning parameters.

[0055] By adopting the above technical solutions, through credibility assessment and image feature analysis, the type and area of ​​occlusion can be accurately identified; for close-range coverage occlusion, precise and efficient lens cleaning is achieved through parameterized cleaning control, providing continuous and stable visual perception capabilities for the autonomous driving system.

[0056] Optional, also includes:

[0057] When the specific occlusion state is not the preset close-range coverage occlusion, the relative motion vector is determined based on the occlusion image information and the specific occlusion area;

[0058] The target obstacle avoidance direction is determined based on the relative motion vector;

[0059] Determine the gimbal deflection parameters based on the target obstacle avoidance direction;

[0060] Control the camera's pan-tilt unit to perform obstacle avoidance maneuvers according to the pan-tilt unit deflection parameters.

[0061] By adopting the above technical solution, the optimal obstacle avoidance angle of the gimbal is dynamically calculated by analyzing the relative motion trend of the obstruction, enabling the camera to actively deviate from the obstruction trajectory and restore the effective field of view, thus providing a more stable and reliable data source for the environmental perception system.

[0062] Optional, also includes:

[0063] After controlling the camera pan-tilt unit to perform obstacle avoidance movements according to the pan-tilt unit deflection parameters or to perform directional cleaning of the camera lens according to the air blowing cleaning parameters, image information is collected and processed.

[0064] Determine the camera's credibility assessment value based on processed image information;

[0065] When the camera's confidence assessment value reaches the preset recovery threshold, the camera's normal weight in the perception fusion algorithm is restored.

[0066] When the camera confidence assessment value does not reach the preset recovery threshold, the camera data is kept at the lowest weight level and the multi-sensor data compensation mechanism is activated.

[0067] By adopting the above technical solutions, a reliable basis for the dynamic adjustment of perception weights is provided by quantitatively evaluating the image quality after clearing or obstacle avoidance. The weight recovery mechanism based on credibility scoring ensures the rapid reuse of the system after the camera performance is restored, while the compensation activation when the standard is not met ensures the continuous reliability of the perception system, effectively improving the self-repair capability and overall robustness of the perception system.

[0068] Secondly, this application provides a functional safety and expected function assurance system for an on-board bus, employing the following technical solution:

[0069] A functional safety and expected function assurance system for an onboard bus includes:

[0070] The acquisition module is used to collect operating status signals, environmental perception data, and reliability assessment values.

[0071] A memory for storing programs that implement a method for ensuring the functional safety and intended functionality of an onboard bus;

[0072] The processor is used to load and execute programs stored in memory.

[0073] In summary, this application includes at least one of the following beneficial technical effects:

[0074] 1. By processing operational status signals and environmental perception data in parallel, synchronous monitoring and diagnosis of hardware faults and perceived risks are achieved. Based on the dynamic matching of fault level and risk level, a coordinated safety response strategy and expected functional safety handling strategy are generated. Finally, through the collaborative execution of the safety island hardware and the main computing unit, a complete safety closed loop from fault handling to risk response is formed. This effectively solves the problem of response conflict and coverage blind spots caused by the isolated operation of functional safety and expected functional safety mechanisms in traditional solutions, and significantly improves the system robustness and overall safety of the vehicle controller in complex operating environments.

[0075] 2. When the system determines a serious fault, the independent takeover of the safety island hardware ensures a seamless transfer of control. The minimum risk path generated by multi-source information fusion guarantees the rationality of the vehicle's hazard avoidance process, while continuous status monitoring and safe stopping judgment realize closed-loop management of the hazard avoidance process. Furthermore, direct control of the underlying hardware avoids the risk of execution failure caused by main system failures, and the dynamic fusion of environmental perception and vehicle status ensures the optimization of the hazard avoidance strategy. Finally, system safety locking and remote alarms complete the entire process of protection from fault occurrence to the maintenance of a safe state, significantly improving the system's survivability in serious fault scenarios.

[0076] 3. When the system identifies a high risk, it achieves isolation and intelligent repair of perceived data through fault tolerance and compensation mechanisms. By fusing historical environmental data with real-time data from multiple sensors, the reliability of environmental perception is effectively improved. A high-confidence environmental model generated based on the corrected data provides an accurate basis for risk reassessment. Finally, through dynamic decision-making based on the function execution state, the system achieves smooth degradation and safe recovery under abnormal perception conditions, ensuring the continuous safe operation of autonomous driving functions in uncertain scenarios. Attached Figure Description

[0077] Figure 1 This is a flowchart of a method for ensuring the functional safety and expected functionality of an onboard bus.

[0078] Figure 2 This is a flowchart illustrating the expected functional safety risk handling process;

[0079] Figure 3 This is a flowchart illustrating the functional safety monitoring and response mechanism. Detailed Implementation

[0080] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments.

[0081] Reference Figure 1 , Figure 2 and Figure 3 This application discloses a method for ensuring the functional safety and expected functionality of an onboard bus, comprising the following steps:

[0082] S10: Collect the operating status signal of the main computing unit.

[0083] The running status signals refer to the heartbeat signal of the main computing unit, the memory CRC / ECC error signal, the CPU / GPU load rate, and the critical task timeout signal.

[0084] The system acquires heartbeat packets from the main computing unit in real time via hardware monitoring circuitry, reads ECC error counts from the memory controller, obtains CPU / GPU load rates through performance counters, and acquires task execution times using timestamps from the real-time operating system. The specific signal acquisition circuitry and timing are designed by those skilled in the art based on the system architecture and will not be elaborated upon here.

[0085] S11: Perform fault diagnosis based on operating status signals to obtain the fault level.

[0086] Fault levels refer to the different levels of faults that classify abnormal system states, namely Level 1 (critical fault), Level 2 (moderate fault) and Level 3 (minor fault).

[0087] The specific methods for determining the fault level will be explained in detail in subsequent sections S20 to S23, and will not be repeated here.

[0088] S12: Determine the safety response strategy based on the fault level.

[0089] Safety response strategies refer to the handling plans for different levels of faults.

[0090] The security response strategy corresponding to the fault level can be obtained by querying the preset response strategy library.

[0091] The response strategy library stores different safety response strategies corresponding to different fault levels. The strategy configurations in the response strategy library are preset by those skilled in the art according to functional safety requirements, and will not be elaborated here.

[0092] S13: Collect environmental perception data and credibility assessment values.

[0093] Environmental perception data refers to raw data from multiple sensors, such as camera images, radar point clouds, and lidar scanning data, as well as the fused target list.

[0094] Environmental perception data is acquired through time-synchronized acquisition by multiple sensors, including cameras that capture 1920×1080 resolution images at 30fps, radar that outputs point cloud data at 10Hz, and lidar that performs 360° scanning at 20Hz.

[0095] The confidence score refers to the confidence score calculated using a sensor data quality assessment algorithm.

[0096] The raw data is spatiotemporally aligned using a multi-sensor data fusion module, and target tracking is performed using Kalman filtering. Simultaneously, a data consistency check algorithm is used to calculate the reliability score of each sensor's data, i.e., the reliability assessment value. The specific data fusion algorithm and reliability calculation method are determined by those skilled in the art based on the sensor characteristics and will not be elaborated upon here.

[0097] S14: Combine environmental perception data with credibility assessment values ​​to conduct an expected functional safety risk assessment to obtain the risk level.

[0098] Risk level refers to the level of safety risk classified based on perceived uncertainty.

[0099] The risk level is determined by establishing an evaluation system that includes target false detection rate, false detection rate, positioning error, and sensor coverage. This involves analyzing the spatiotemporal consistency of data from various sensors, assessing the distribution characteristics and anomaly patterns of reliability evaluation values, and using fuzzy inference to calculate risk coefficients across all indicators. Finally, based on the range of these risk coefficients, the risk is categorized into three levels: low risk, medium risk, and high risk. Specific weighting of evaluation indicators, fuzzy inference rules, and risk level classification thresholds are determined by those skilled in the art based on actual application needs and will not be elaborated upon here.

[0100] S15: Match the expected functional safety handling strategy according to the risk level.

[0101] The intended functional safety handling strategy refers to the functional restrictions and risk mitigation measures taken for different risk levels.

[0102] By querying the preset processing strategy library, the expected functional safety processing strategy corresponding to the risk level can be matched. The strategy library stores the mapping relationship between different risk levels and processing strategies. The specific content of the strategy library is pre-configured by those skilled in the art according to the expected functional safety requirements, and will not be elaborated here.

[0103] S16: Control the security island hardware and the main computing unit to collaboratively execute security response strategies and expected functional safety processing strategies to achieve dual protection of functional safety and expected functional safety.

[0104] Control commands are synchronized through a communication interface between the safety island and the main controller, and a priority arbitration mechanism coordinates the allocation of control between the two. When the safety island detects a fault in the main controller, it immediately takes over the underlying control of the vehicle; when the main controller identifies an anticipated functional safety risk, it sends a cooperative control request to the safety island. This achieves dual protection of functional safety and anticipated functional safety, ensuring that the vehicle maintains a safe operating state under various abnormal conditions. The specific cooperative control logic and fault switching process are designed by those skilled in the art based on the system architecture and will not be elaborated here.

[0105] It also includes methods for determining the fault level:

[0106] S20: Obtain abnormal characteristic parameters based on the operating status signal.

[0107] Abnormal characteristic parameters refer to quantitative abnormal indicators extracted from operating status signals.

[0108] Anomaly characteristic parameters were obtained by analyzing the variance of heartbeat signal intervals, memory CRC / ECC error rates, CPU / GPU load rate fluctuations, and critical task timeout distribution characteristics. Specific feature extraction algorithms are selected by those skilled in the art based on signal characteristics and will not be elaborated upon here.

[0109] S21: Determine the number of abnormal features based on the abnormal feature parameters.

[0110] The number of abnormal features refers to the number of abnormal features that exceed the threshold.

[0111] The number of abnormal feature parameters exceeding a preset threshold is obtained by comparing each abnormal feature parameter with that threshold. The specific threshold settings are determined by those skilled in the art through system testing and will not be elaborated upon here.

[0112] S22: Calculate the system health score by the number of abnormal features.

[0113] System health score is a quantitative value that characterizes the overall state of a system.

[0114] A weighted summation method is used to calculate the health score based on the number of abnormal features and their weights. The weighting is determined by those skilled in the art through importance analysis and will not be elaborated here.

[0115] S23: Determine the fault level based on the system health score using preset fault level mapping rules.

[0116] The fault level mapping rule refers to the correspondence between health scores and fault levels. The fault level mapping rule is pre-defined by those skilled in the art and will not be elaborated upon here.

[0117] By querying the fault level mapping rules, the health score is mapped to the corresponding fault level. The specific values ​​in the mapping table are set by those skilled in the art based on system reliability requirements, and will not be elaborated here.

[0118] Security response strategies include:

[0119] S30: When the fault level is the preset severe fault level, the independent safety island hardware takes over the vehicle's underlying control and collects the vehicle's current operating status and current environmental information.

[0120] A severe fault level refers to a system health score below 40 or a detected loss of heartbeat. Specific scoring thresholds and fault determination criteria are set by those skilled in the art based on system reliability requirements and will not be elaborated upon here.

[0121] The current operating status of a vehicle refers to parameters such as vehicle speed, acceleration, and yaw rate.

[0122] The vehicle's current operating status is acquired in real time via the vehicle's CAN bus.

[0123] Current environmental information refers to environmental elements such as lane lines, obstacles, and traffic signs.

[0124] Current environmental information is acquired through a multi-sensor fusion system, where cameras detect lane lines and traffic signs, while radar and lidar detect the position and movement of obstacles. Sensor data is synchronized in time and coordinates before outputting a complete environmental perception result. Specific sensor configurations and fusion algorithms are designed by those skilled in the art based on system requirements and will not be elaborated upon here.

[0125] When the fault level is a severe fault, the emergency handling procedure of the safety island must be initiated immediately, including: cutting off the main controller's control over the vehicle chassis, allowing the safety island to directly take over the braking, steering, and power systems, and collecting the vehicle's current operating status and current environmental information for subsequent steps.

[0126] S31: Determine the path with the least risk based on the vehicle's current operating status and current environmental information.

[0127] The least risk path is the trajectory path that ensures the safe stopping of a vehicle.

[0128] The safe braking distance is calculated by first analyzing the vehicle's current speed, acceleration, and road curvature, and then combining this with real-time perceived lane line and obstacle location information. Available shoulder areas are then selected from an electronic map, and finally, a smooth transition path, i.e., the minimum risk path, is generated using a fifth-order polynomial curve. The specific path planning algorithm is designed by those skilled in the art based on vehicle control characteristics and will not be elaborated upon here.

[0129] S32: Controls the safety island hardware to perform basic braking and steering operations, guides the vehicle to travel along the path of least risk, and collects vehicle position and attitude information.

[0130] Vehicle location information refers to the vehicle's current location coordinates.

[0131] The vehicle's location information is obtained through the vehicle's GPS positioning.

[0132] Vehicle attitude information refers to parameters such as roll angle and pitch angle obtained through an inertial measurement unit.

[0133] After obtaining the minimum risk path, the vehicle's actuators need to be directly controlled via the safety island hardware. Basic braking is achieved by controlling the hydraulic braking system, and basic steering is achieved by controlling the electric power steering system. The safety island uses a PID control algorithm to track the minimum risk path, while simultaneously collecting GPS positioning data and inertial measurement unit data in real time for closed-loop control. Specific control parameters are determined by those skilled in the art through vehicle dynamics testing and will not be elaborated upon here.

[0134] S33: Determine whether the vehicle is in a safe parking state by using vehicle location information, vehicle attitude information, and current environmental information.

[0135] A safe parking state refers to a state in which a vehicle comes to a complete stop within a safe area.

[0136] A comprehensive judgment is made by analyzing factors such as whether the vehicle is within a safe zone, whether its speed is zero, and whether its distance from obstacles is safe. Specific safety conditions are set by those skilled in the art according to standard requirements and will not be elaborated upon here.

[0137] S34: When the vehicle is in a safe parking state, the system safety lock is triggered and a remote alarm message is sent.

[0138] When the vehicle is in a safe parking state, the parking brake must be activated via the safety island hardware to cut off the power supply to the power system, and an alarm message must be sent to the monitoring center via the onboard communication module. The specific locking logic and communication protocol are designed by those skilled in the art based on functional safety requirements, and will not be elaborated here.

[0139] Security response strategies also include:

[0140] S40: When the fault level is not the preset severe fault level, a function degradation scheme is matched from the preset degradation strategy library according to the fault level.

[0141] Functional degradation schemes refer to strategies that restrict some autonomous driving functions.

[0142] By querying the degradation strategy library, functional restriction schemes corresponding to different fault levels can be obtained. For example, a level 2 fault corresponds to "limiting the maximum vehicle speed to 60km / h and disabling the automatic lane change function," while a level 3 fault corresponds to "keeping the lane center function but prompting the driver to take over." The specific schemes in the strategy library are pre-configured by those skilled in the art according to functional safety requirements, and will not be elaborated here.

[0143] When the fault level is not a severe fault level, it indicates that the system still possesses basic operational capabilities and can maintain core safety functions through functional degradation. In this case, the system maintains redundant monitoring mode, gradually reducing the level of automated driving while ensuring safety, and allowing sufficient transition time for driver takeover. Therefore, a functional degradation plan must be determined first for subsequent steps. Specific degradation transition strategies are designed by those skilled in the art based on the principles of human-machine co-driving and will not be elaborated upon here.

[0144] S41: Determine the scope of restricted functions based on the function degradation scheme.

[0145] The scope of restricted functions refers to the list of autonomous driving functions that need to be disabled or restricted.

[0146] By analyzing the specific restrictions in the function degradation scheme, the autonomous driving functions that need to be disabled or restricted are extracted to form a complete list of restricted functions. For example, in the scheme of "limiting the maximum vehicle speed to 60km / h and disabling the automatic lane changing function," the scope of restricted functions includes vehicle speed control functions and automatic lane changing functions. The specific rules for parsing function items are determined by those skilled in the art based on the system architecture and will not be elaborated here.

[0147] S42: Control the redundant computing unit to take over the computing tasks of the main computing unit, and perform the corresponding functional restriction operations according to the restricted functional range and prompt the driver to take over, while collecting the driver's status information.

[0148] Driver status information refers to attention parameters such as facial orientation, eyelid opening, and gaze direction, as well as operational readiness indicators such as hand grip on the steering wheel, collected through a driver monitoring system. Specific data collection schemes are designed by those skilled in the art based on human factors engineering requirements and will not be elaborated upon here.

[0149] The redundant computing unit synchronizes the operating status of the main computing unit in real time through a hot backup mechanism. When a failure of the main computing unit is detected, task takeover is completed within 10ms. Based on the limited functional scope, the system will automatically disable relevant autonomous driving functions and prompt the driver to take over through a multimodal human-machine interface (including visual cues, auditory alarms, and tactile feedback). The specific takeover timing design is determined by those skilled in the art based on the system's real-time requirements and will not be elaborated here.

[0150] S43: Assess takeover readiness based on driver status information.

[0151] Takeover readiness refers to the score of a driver's readiness to take over a vehicle.

[0152] By analyzing state parameters such as the driver's facial orientation, gaze focus area, and the strength and position of their hands on the steering wheel, a weighted scoring algorithm is used to calculate the driver's readiness to take over. A high readiness level is determined when the driver's face is directly facing forward, their gaze is focused on the road, and both hands are on the steering wheel; a low readiness level is determined when the driver's gaze deviates from the road or their hands leave the steering wheel. The specific scoring algorithm and judgment thresholds are determined by those skilled in the art through human factors engineering testing and will not be elaborated here.

[0153] S44: Determine the alarm level and prompting method based on the takeover readiness level, and provide prompts based on the alarm level and prompting method. When effective driver takeover is detected, gradually disengage the autonomous driving function.

[0154] Alarm levels refer to the warning levels classified according to the degree of urgency.

[0155] The prompting method refers to a combination of multimodal prompts, such as visual, auditory, and tactile prompts.

[0156] The alarm level and notification method corresponding to the takeover readiness are matched by querying a preset alarm strategy library. When the takeover readiness is low, a level 1 alarm is used, combining a red flashing indicator on the dashboard, a continuous buzzer, and steering wheel vibration; when the takeover readiness is medium, a level 2 alarm is used, combining a yellow flashing indicator on the dashboard and an intermittent buzzer; when the takeover readiness is high, a level 3 alarm is used, with only a green indicator light on the dashboard providing notification. The specific alarm strategy configuration is determined by those skilled in the art based on ergonomic principles and will not be elaborated here.

[0157] When the system detects effective driver takeover through the steering wheel torque sensor and driver input commands, it initiates the automatic driving function exit procedure: first, lateral control privileges are released while longitudinal control assistance is maintained; after confirming stable driver control, longitudinal control privileges are gradually released, ultimately exiting the automatic driving function completely. The specific privilege transfer procedure and exit time parameters are determined by those skilled in the art based on vehicle dynamics characteristics and will not be elaborated here.

[0158] The expected functional safety handling strategy includes:

[0159] S50: When the risk level is high, activate the preset fault tolerance and compensation mechanism to output uncertainty warnings to the human-computer interaction interface and reduce the system function confidence level.

[0160] Fault tolerance and compensation mechanisms refer to security protection mechanisms that isolate perceived anomalies and compensate for data errors.

[0161] When the risk level is high, the system immediately creates an independent software container to isolate the abnormal sensor data and simultaneously initiates a compensation algorithm based on historical environmental data and multi-sensor fusion. A "Perception System Limited" warning is output through the human-machine interface, and the system's functional confidence level is lowered. Specific container resource configurations and confidence level adjustment strategies are determined by those skilled in the art based on the system architecture and will not be elaborated upon here.

[0162] S51: Collects historical environmental data and real-time data from multiple sensors.

[0163] Historical environmental data refers to historical information such as road structure and traffic participants recorded during normal system operation.

[0164] The system reads environmental perception records from the past 5 minutes via a data storage module, including structured data such as lane curvature, traffic sign positions, and obstacle movement trajectories. Historical environmental data is stored in time-series format on the vehicle's solid-state drive, with a data update frequency of 10Hz. The specific data storage format is designed by those skilled in the art based on system requirements and will not be elaborated here.

[0165] Multi-sensor real-time data refers to the synchronously collected data from sensors such as cameras, radar, and lidar at the current moment. Through timestamp alignment and data fusion processing, unified environmental perception information is formed. The specific sensor synchronization mechanism is designed by those skilled in the art based on the system architecture and will not be elaborated upon here.

[0166] S52: Based on historical environmental data and real-time data from multiple sensors, the environmental perception data is corrected using a preset compensation algorithm.

[0167] The compensation algorithm refers to the calculation method used to correct anomaly-sensing data. The compensation algorithm is predetermined by those skilled in the art and will not be described in detail here.

[0168] After obtaining historical environmental data and real-time data from multiple sensors, the environmental perception data needs to be corrected through a compensation algorithm. The specific implementation process of the compensation algorithm will be explained in detail in the intelligent compensation methods of S60 to S63, and will not be repeated here.

[0169] S53: Generate a high-confidence environmental model based on the revised environmental perception data, and reassess the risk level based on the high-confidence environmental model.

[0170] A high-confidence environment model refers to a reliable environmental perception result generated through multi-source data fusion and compensation. This model includes complete road structure information, accurate obstacle location data, and validated trajectories of traffic participants.

[0171] By inputting the corrected environmental perception data into the environmental modeling algorithm, a vector map containing elements such as lane lines, curbs, and obstacles is constructed, and the confidence scores of each element are labeled, ultimately generating a high-confidence environmental model. Based on this model, risk assessment indicators such as target false negative rate and positioning error are recalculated, and the risk level is updated. The specific model generation and risk assessment methods are designed by those skilled in the art according to system requirements and will not be elaborated here.

[0172] S54: Decision on the execution status of the target autonomous driving function based on the reassessed risk level.

[0173] The decision-making logic module determines whether to continue executing the autonomous driving function: if the risk level is low, maintain the current function; if the risk level is medium, downgrade to execute some functions; if the risk level is high, immediately disengage autonomous driving. Specific decision-making rules are set by those skilled in the art based on functional safety requirements and will not be elaborated here.

[0174] It also includes intelligent compensation methods:

[0175] S60: Generate a normal data feature library based on historical environmental data, and retrieve historical normal data based on the normal data feature library.

[0176] The normal data feature library refers to the set of data features of a sensor under normal operating conditions.

[0177] Historical normal data refers to data samples collected under normal sensor operating conditions, retrieved from a feature library and matching the current environmental conditions. These data samples, after being timestamped and spatially registered, can be used for subsequent data compensation processing.

[0178] By performing cluster analysis on historical environmental data, the data distribution characteristics of each sensor under normal operating conditions are extracted, including parameters such as numerical range, trend, and correlation, and an indexed feature library is established. When historical normal data needs to be retrieved, the most similar data sample is matched from the feature library based on the current environmental scenario. The specific feature extraction and matching algorithms are determined by those skilled in the art based on the data type and will not be elaborated here.

[0179] S61: Identify abnormal sensing data based on a normal data feature library and real-time data from multiple sensors.

[0180] Abnormal sensing data refers to sensor data that deviates significantly from normal characteristics.

[0181] By calculating similarity, the degree of matching between real-time data and a normal feature library is compared to identify abnormal data segments. The specific similarity algorithm is determined by those skilled in the art based on the feature type and will not be elaborated here.

[0182] S62: Generate data compensation parameters based on historical normal data and real-time data from multiple sensors.

[0183] Data compensation parameters refer to the interpolation coefficients and weighting parameters used to correct outlier data.

[0184] By analyzing the correlation between historical normal data and real-time data from multiple sensors using least squares regression, a mapping model between the sensors is established, thereby calculating the interpolation coefficients and fusion weights of each sensor. The specific regression model and parameter calculation methods are determined by those skilled in the art based on the sensor characteristics and will not be elaborated upon here.

[0185] S63: Correct the abnormal perception data based on the data compensation parameters, thereby completing the correction of the environmental perception data.

[0186] Data interpolation and extrapolation algorithms are used to repair abnormal perception data based on compensation parameters, restoring complete environmental perception information. Specific correction algorithms are determined by those skilled in the art based on the anomaly type and will not be elaborated upon here.

[0187] Also includes:

[0188] S70: Determines the camera's operational status based on confidence assessment values.

[0189] Camera working status refers to whether the camera is working properly, blocked, or malfunctioning.

[0190] By analyzing the time-series characteristics of the reliability assessment values ​​and combining them with image quality indicators (such as sharpness, contrast, and noise level), the working status of the camera is determined. When the reliability assessment value consistently falls below a threshold and the image quality significantly deteriorates, it is determined that the camera is obstructed; when no valid image data can be obtained at all, it is determined that the camera is malfunctioning. The specific thresholds for determination are determined by those skilled in the art through experimental data and will not be elaborated here.

[0191] S71: When the camera is in a camera-occluded state, collect occluded image information.

[0192] Camera obstruction refers to a state where the lens is covered by dirt, resulting in a decrease in image quality.

[0193] Occlusion image information refers to images that contain occlusion features. Occlusion image information can be obtained by capturing images with a camera.

[0194] When the camera is in the "camera obstructed" state, it means that the camera is being obstructed during shooting, and the obstruction image information needs to be collected first for subsequent steps.

[0195] S72: Extract features of the occluded region from the occluded image information to obtain the specific occlusion state.

[0196] The specific occlusion status refers to the quantitative characteristics such as the occlusion area, location, and shape.

[0197] By analyzing the pixel distribution characteristics of the occluded area using image processing algorithms, calculating the proportion of the occluded area to the total image area, determining the position coordinates of the occluded area in the image coordinate system, and extracting the geometric shape features of the occlusion contour, the specific occlusion state can be obtained. The specific feature extraction algorithm is determined by those skilled in the art based on the image characteristics and will not be elaborated upon here.

[0198] S73: Identify specific occlusion areas based on occlusion image information and preset occlusion features.

[0199] Occlusion features refer to image feature templates of typical occlusion objects. Occlusion features are pre-defined by those skilled in the art and will not be elaborated upon here.

[0200] Specifically, the occluded area refers to the location result of the occluded pixel area in the image.

[0201] By comparing the current occluded image with the occlusion features pixel by pixel, and combining this with a region growing algorithm, the boundary coordinates of the occluded region can be accurately located, thus obtaining the specific occluded region.

[0202] S74: When the specific occlusion state is the preset close-range coverage occlusion, determine the blowing cleaning parameters according to the specific occlusion area, and perform directional cleaning of the camera lens according to the blowing cleaning parameters.

[0203] Close-range coverage refers to the state where the obstruction is directly attached to the surface of the lens.

[0204] The cleaning parameters for blower cleaning include cleaning control parameters such as airflow intensity, spray angle, and duration.

[0205] By consulting a pre-defined cleaning parameter reference table, the corresponding combination of cleaning parameters is matched based on the obstruction area, obstruction location, and obstruction type. This reference table records the airflow intensity, spray angle, and duration corresponding to different obstruction characteristics. For example, an airflow intensity of 0.2 MPa is used when the obstruction area is less than 10%, 0.35 MPa when the obstruction area is 10%–30%, and 0.5 MPa when the obstruction area is greater than 30%. The horizontal and vertical deflection angles of the spray device are calculated based on the coordinates of the center position of the obstruction area. A duration of 2 seconds is set for dust obstructions, and a duration of 3 seconds is set for water stain obstructions. The specific values ​​in the cleaning parameter reference table are determined by those skilled in the art through cleaning effect testing and will not be elaborated here.

[0206] Also includes:

[0207] S80: When the specific occlusion state is not the preset close-range coverage occlusion, the relative motion vector is determined based on the occlusion image information and the specific occlusion area.

[0208] The relative motion vector refers to the motion parameters of the obstruction relative to the camera.

[0209] By analyzing the positional changes of the occluded region in multiple consecutive frames of occluded images, the displacement vector and velocity of the occluded object in the image coordinate system are calculated. The specific motion estimation algorithm is determined by those skilled in the art based on the characteristics of the image sequence and will not be elaborated here.

[0210] S81: Determine the target obstacle avoidance direction based on the relative motion vector.

[0211] The target obstacle avoidance direction refers to the angle at which the camera gimbal needs to deflect to avoid obstructions.

[0212] By consulting a pre-defined obstacle avoidance direction lookup table, the target obstacle avoidance direction corresponding to the relative motion vector can be obtained. This lookup table records the mapping relationship between different motion directions and gimbal deflection angles. For example, when the relative motion direction is in the upper left quadrant and the speed is greater than 2 pixels / frame, the gimbal deflects 15° to the lower right; when the relative motion direction is directly to the left and the speed is between 1 and 2 pixels / frame, the gimbal deflects 10° to the right. The specific values ​​in the lookup table have been determined by those skilled in the art through actual testing and are not elaborated here.

[0213] S82: Determine the gimbal deflection parameters based on the target obstacle avoidance direction.

[0214] The gimbal deflection parameters refer to the target angle and angular velocity that control the movement of the gimbal.

[0215] By consulting a pre-defined gimbal parameter lookup table, the gimbal deflection parameters corresponding to the target obstacle avoidance direction can be obtained. This lookup table records the target angle and angular velocity combinations corresponding to different obstacle avoidance directions. For example, a 15° obstacle avoidance direction corresponds to a target angle of 15° and an angular velocity of 30° / s; a 30° obstacle avoidance direction corresponds to a target angle of 30° and an angular velocity of 45° / s. The specific parameter correspondences are determined by those skilled in the art based on the gimbal performance indicators and will not be elaborated here.

[0216] S83: Controls the camera gimbal to perform obstacle avoidance maneuvers according to the gimbal deflection parameters.

[0217] Once the gimbal deflection parameters are obtained, the camera gimbal needs to be controlled to perform obstacle avoidance movements according to the gimbal deflection parameters, so that the camera's field of view avoids obstructed areas.

[0218] Also includes:

[0219] S90: After controlling the camera pan-tilt unit to perform obstacle avoidance movements according to the pan-tilt unit deflection parameters or to perform directional cleaning of the camera lens according to the air blowing cleaning parameters, image information is acquired and processed.

[0220] Image information processing refers to the re-acquisition of camera images after clearing or obstacle avoidance operations.

[0221] Image information is obtained through camera capture.

[0222] After controlling the camera pan-tilt unit to perform obstacle avoidance movements according to the pan-tilt unit deflection parameters or to perform directional cleaning of the camera lens according to the air blowing cleaning parameters, image information needs to be collected and processed for subsequent steps.

[0223] S91: Determine the camera credibility assessment value based on processed image information.

[0224] The camera credibility assessment value refers to a quantitative score of the quality of the processed image.

[0225] By analyzing quality indicators such as image sharpness, contrast, and noise level after processing, and combining the results of multi-sensor data consistency verification, a weighted scoring method is used to calculate the camera's reliability assessment value. Specific scoring criteria and weighting configurations are determined by those skilled in the art based on image quality requirements and will not be elaborated upon here.

[0226] S92: When the camera confidence assessment value reaches the preset recovery threshold, restore the normal weight of the camera in the perception fusion algorithm.

[0227] The recovery threshold is a confidence score for determining whether a camera has resumed normal operation. The recovery threshold is set in advance by those skilled in the art and will not be elaborated here.

[0228] When the camera's confidence assessment value exceeds the recovery threshold, it indicates that the camera's imaging quality has returned to normal and it can once again participate in environmental perception as a reliable sensing source. At this point, the system gradually restores the camera's weight in the perception fusion algorithm from the lowest level to its normal value. The recovery process employs a gradual adjustment strategy to avoid abrupt changes in the fusion result. The specific weight recovery rate is determined by those skilled in the art based on system stability requirements and will not be elaborated here.

[0229] S93: When the camera confidence assessment value does not reach the preset recovery threshold, keep the camera data at the lowest weight level and start the multi-sensor data compensation mechanism.

[0230] When the camera's confidence assessment value fails to reach the recovery threshold, it indicates that the camera's imaging quality still does not meet the system's reliability requirements. In this case, the camera data is maintained at its lowest weight in the perception fusion algorithm, while a multi-sensor data compensation algorithm based on radar and lidar is activated. This multi-source data fusion ensures the integrity and accuracy of environmental perception.

[0231] Based on the same inventive concept, embodiments of the present invention provide a functional safety and expected function assurance system for an in-vehicle bus, comprising:

[0232] The data acquisition module is used to collect operating status signals, environmental perception data, confidence assessment values, current vehicle operating status, current environmental information, vehicle location information, vehicle attitude information, driver status information, historical environmental data, real-time data from multiple sensors, occlusion image information, and process image information.

[0233] A memory for storing programs that implement a method for ensuring the functional safety and intended functionality of an onboard bus;

[0234] The processor is used to load and execute programs stored in memory.

[0235] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0236] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A method for ensuring the functional safety and intended functionality of an onboard bus, characterized in that, include: Collect the operating status signals of the main computing unit; Fault diagnosis is performed based on operating status signals to determine the fault level; Determine the safety response strategy based on the fault level; Collect environmental perception data and credibility assessment values; By combining environmental perception data and credibility assessment values, an expected functional safety risk assessment is conducted to obtain the risk level. Match the expected functional safety handling strategy according to the risk level; The control security island hardware and the main computing unit work together to execute security response strategies and expected functional safety processing strategies to achieve dual protection of functional safety and expected functional safety. The security response strategy includes: When the fault level is the preset severe fault level, the independent safety island hardware takes over the vehicle's underlying control and collects the vehicle's current operating status and current environmental information. Determine the least risk path based on the vehicle's current operating status and current environmental information; The control safety island hardware performs basic braking and steering operations, guides the vehicle to travel along the path of least risk, and collects vehicle position and attitude information. Determine whether a vehicle is in a safe parking state by using vehicle location information, vehicle posture information, and current environmental information; When the vehicle is in a safe parking state, the system safety lock is triggered and a remote alarm message is sent; The security response strategy also includes: When the fault level is not the preset severe fault level, a function degradation scheme is matched from the preset degradation strategy library according to the fault level. Determine the scope of restricted functions based on the function degradation scheme; The redundant computing unit takes over the computing tasks of the main computing unit, performs corresponding functional limitation operations according to the limited functional range, prompts the driver to take over, and collects the driver's status information at the same time. Assess takeover readiness based on driver status information; The alarm level and prompting method are determined based on the takeover readiness level, and prompts are given based on the alarm level and prompting method. When effective driver takeover is detected, the automatic driving function is gradually disengaged. The anticipated functional safety handling strategy includes: When the risk level is high, the preset container and compensation mechanism are activated to output uncertainty warnings to the human-computer interaction interface and reduce the system function confidence level. Collect historical environmental data and real-time data from multiple sensors; Based on historical environmental data and real-time data from multiple sensors, a preset compensation algorithm is used to correct the environmental perception data. A high-confidence environmental model is generated based on the revised environmental perception data, and the risk level is reassessed based on the high-confidence environmental model. The decision-making process will be based on the reassessed risk level to determine the execution status of the target autonomous driving function.

2. The method for ensuring the functional safety and intended functionality of an on-board bus according to claim 1, characterized in that, It also includes methods for determining the fault level: Abnormal characteristic parameters are obtained based on operating status signals; The number of abnormal features is determined based on the abnormal feature parameters; The system health score is calculated by the number of abnormal features. The fault level is determined based on the system health score and a preset fault level mapping rule.

3. The method for ensuring the functional safety and intended functionality of an on-board bus according to claim 1, characterized in that, It also includes intelligent compensation methods: A normal data feature library is generated based on historical environmental data, and historical normal data is retrieved based on the normal data feature library. Based on a normal data feature library and real-time data from multiple sensors, abnormal sensing data is identified. Data compensation parameters are generated based on historical normal data and real-time data from multiple sensors. The abnormal perception data is corrected based on the data compensation parameters, thereby completing the correction of the environmental perception data.

4. The method for ensuring the functional safety and intended functionality of an on-board bus according to claim 1, characterized in that, Also includes: The camera's operational status is determined based on a confidence level assessment. When the camera is in an obstructed state, it collects obstructed image information. Feature extraction of the occluded region is performed from the occluded image information to obtain the specific occlusion status; Identify specific occlusion areas based on occlusion image information and preset occlusion features; When the specific occlusion state is the preset close-range coverage occlusion, the blowing cleaning parameters are determined according to the specific occlusion area, and the camera lens is cleaned in a targeted manner according to the blowing cleaning parameters.

5. The method for ensuring the functional safety and intended functionality of an on-board bus according to claim 4, characterized in that, Also includes: When the specific occlusion state is not the preset close-range coverage occlusion, the relative motion vector is determined based on the occlusion image information and the specific occlusion area; The target obstacle avoidance direction is determined based on the relative motion vector; Determine the gimbal deflection parameters based on the target obstacle avoidance direction; Control the camera's pan-tilt unit to perform obstacle avoidance maneuvers according to the pan-tilt unit deflection parameters.

6. The method for ensuring the functional safety and intended functionality of an on-board bus according to claim 5, characterized in that, Also includes: After controlling the camera pan-tilt unit to perform obstacle avoidance movements according to the pan-tilt unit deflection parameters or to perform directional cleaning of the camera lens according to the air blowing cleaning parameters, image information is collected and processed. Determine the camera's credibility assessment value based on processed image information; When the camera's confidence assessment value reaches the preset recovery threshold, the camera's normal weight in the perception fusion algorithm is restored. When the camera confidence assessment value does not reach the preset recovery threshold, the camera data is kept at the lowest weight level and the multi-sensor data compensation mechanism is activated.

7. A functional safety and expected function assurance system for an on-board bus, characterized in that, include: The acquisition module is used to collect operating status signals, environmental perception data, and reliability assessment values. A memory for storing a program that implements a method for ensuring the functional safety and intended functionality of an onboard bus as described in any one of claims 1 to 6; The processor is used to load and execute programs stored in memory.