Intelligent scheduling and optimization system for AGV production line

By constructing a closed-loop control system for AGV production lines, including status aggregation, interlock management, and permission scheduling, the problems of deadlock and congestion in the passage of AGV production line systems under multiple concurrent vehicles were solved, achieving stable and self-recovering passage order and improving the system's operational controllability and scheduling continuity.

CN121857593BActive Publication Date: 2026-07-21HUNAN ABBOTT ROBOT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUNAN ABBOTT ROBOT TECH CO LTD
Filing Date
2026-01-23
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing AGV production line systems are prone to traffic deadlock, congestion, and unstable scheduling issues in scenarios such as multiple vehicles operating concurrently, narrow passages, and intersections, making it difficult to establish a sustainable and self-recoverable stable traffic order.

Method used

A closed-loop control system is constructed, which integrates status aggregation, interlock management, permit scheduling, rollback recovery, and security linkage. Through a dual confirmation mechanism of status frames and event receipts, the system manages the mutual exclusion table and interlock condition set of controlled access resources, performs pre-occupancy registration and permit application waiting timer, and combines personnel detection and emergency stop signal-triggered speed limit strategies to achieve self-recovering access optimization.

Benefits of technology

It improves the stability of AGV production lines in scenarios with multiple vehicles operating concurrently and channel conflicts, ensures continuous scheduling and controllable operation, avoids conflicts in narrow channels and intersections, and achieves self-recovery and safety constraints for the production line.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121857593B_ABST
    Figure CN121857593B_ABST
Patent Text Reader

Abstract

The application discloses an AGV production line intelligent scheduling and optimization system and relates to the technical fields of industrial control and intelligent scheduling, and is used for solving the problem of easy deadlock of the production line passing. The application gathers task requests, vehicle states and roadside occupation confirmation under a unified time reference, generates a state frame and an event reply, establishes a controlled passing resource mutual exclusion table and a mutual locking condition set by a mutual locking management module, adopts double confirmation triggering of pre-occupation registration and entering reply occupation confirmation and exit reply idle confirmation, avoids false occupation, a permission scheduling module cuts a control section according to a resource boundary, applies for passing permission before entering, suppresses congestion diffusion, a backtracking recovery module identifies circular waiting or permission timeout, freezes permission and issues a retreat path retreat point confirmation resource release control section reconnection backtracking sequence to realize self-recovery, and a safety linkage module gradually recovers passing according to mutual locking increment rules and permission limit instructions, thereby improving passing stability and controllability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control and intelligent scheduling technology, and more specifically, to an intelligent scheduling and optimization system for AGV production lines. Background Technology

[0002] In the field of intelligent manufacturing production line logistics, material handling and workstation delivery based on AGVs (Automated Guided Vehicles) have been widely used. These systems typically issue handling tasks from a higher-level dispatcher. AGVs execute path planning based on the factory map and interact with other vehicles in shared access areas such as intersections, narrow passages, and automated warehouse entrances. Existing solutions often organize vehicle operation using task queues and rule-based obstacle avoidance, and dynamically dispatch orders through site material requisition, workstation cycle time, and vehicle status feedback to improve production line turnover efficiency. The technical implementation involves the coordination of task allocation, path planning, and on-site control.

[0003] However, dispatch instructions are generated discretely in the upper-level system, while vehicles move continuously in the shared lane and there are communication delays and perception errors. When multiple vehicles approach the entrance of a narrow lane, intersection, or buffer zone at the same time, the order of entry is unclear and the confirmation of occupancy and release is not synchronized, which can lead to mutual waiting, stalemate between vehicles, or entrance congestion. Once personnel temporarily pass through or an emergency stop is triggered on site, the system often handles it with a global pause or coarse-grained prohibition. After the prohibition is lifted, there may be a concentrated rush to pass, causing secondary congestion. This repeatedly interrupts the task execution chain, aggravates the fluctuation of the production line rhythm, and makes it difficult to form a sustainable and self-recoverable stable traffic order. Summary of the Invention

[0004] In order to overcome the above-mentioned defects of the prior art, the following solution is proposed to solve the problem of easy deadlock during production line operation in the above-mentioned background art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: The AGV production line intelligent scheduling and optimization system includes a status aggregation module, an interlock management module, a permission scheduling module, a rollback and recovery module, and a safety linkage module. The modules are connected through data communication. The status aggregation module is used to receive task requests, vehicle status, roadside occupancy confirmations and vacancy confirmations, and generate status frames and event receipts. The interlock management module is used to determine the controlled access resources based on the status frame and establish a mutual exclusion table, generate an interlock condition set and resource state machine, register the pre-occupancy status of the target resource sequence carried by the access permit application, and trigger the transition from the pre-occupancy status to the occupancy status with the entry receipt and occupancy confirmation, and trigger the transition from the occupancy status to the idle status with the exit receipt and idle confirmation. The permit scheduling module is used to generate a task pool and divide the control segment according to the controlled access resource boundary. Before the vehicle enters the control segment, it initiates a pass permit application to the interlock management module, records the permit waiting time and outputs the permit timeout flag, and issues a pass permit order or waiting instruction according to the permit result. The rollback recovery module is used to construct waiting dependencies based on waiting instructions, pre-occupancy status and resource state mechanism, identify cyclic waiting flags or permission timeout flags, freeze the passage permission issuance instructions and issue rollback sequences to selected vehicles. The rollback sequence includes a retreat path, retreat point confirmation, resource release and control segment reconnection. The safety linkage module is used to trigger the switching of operating modes and issue speed limit and prohibition policies based on personnel detection signals or emergency stop signals, inject interlock incremental rules into the interlock management module and issue permission restriction instructions to the permission scheduling module, and issue progressive recovery instructions based on safety release receipts.

[0006] Furthermore, the status aggregation module receives task requests, vehicle status, roadside occupancy confirmations, and idle confirmations, generating status frames and event receipts, including: Extract the task identifier, start identifier, end identifier, and priority flag from the task request, and associate them with the vehicle identifier; Extract pose markers, cargo markers, mission phase markers, and fault markers from the vehicle status and form vehicle status subframes; Extract resource identifiers and confirmation type markers from roadside occupancy and vacancy confirmations, and form roadside status subframes; Perform unified time reference alignment on vehicle state subframes and roadside state subframes, and encapsulate the alignment result into a state frame; The vehicle entry receipt, vehicle exit receipt, roadside occupancy confirmation, and roadside vacancy confirmation are paired according to vehicle identifier and resource identifier, and event receipts are generated and output to the interlock management module and the permit scheduling module.

[0007] Furthermore, the interlock management module determines the controlled access resources based on the state frame and establishes a mutual exclusion table, generating an interlock condition set and a resource state machine, including: The controlled access resource set is determined based on the resource identifier in the roadside status subframe, and an entry point marker and an exit point marker are configured for each controlled access resource. A mutex table is generated based on the set of controlled access resources. The mutex table records resource mutual exclusion pairs and mutual exclusion direction markers. An interlocking condition set is generated based on a mutex table and a state frame. The interlocking condition set includes at least a mutual exclusion occupancy condition, a closed prohibition condition, and a buffer capacity condition. A resource state machine is established based on the interlock condition set. The resource state machine includes idle state, pre-occupied state and occupied state, and a resource state table is generated to output the permission determination result to the permission scheduling module.

[0008] Furthermore, the permit scheduling module generates a task pool and divides the control segment according to the controlled access resource boundary. Before a vehicle enters the control segment, it initiates a access permit application to the interlock management module, records the permit waiting time, and outputs a permit timeout flag, including: The tasks in the task pool are parsed into a sequence of control segments arranged in execution order, and each control segment is bound to a target resource sequence and a candidate yield point marker. A passage permit application is generated for the control segment to be entered. The passage permit application carries the vehicle identification, target resource sequence and entry order mark; After a permit application is initiated, a permit waiting timer is started, and when the permit waiting timer reaches a preset time limit, a permit timeout flag is generated and output to the rollback and recovery module. Receive the permission determination result output by the interlock management module, issue a passage permission order when permission is granted, and issue a waiting instruction with a blocking reason code when permission is denied.

[0009] Furthermore, the interlock management module registers the pre-occupancy status of the target resource sequence carried in the access permit application, and drives the resource state machine to complete the state transition based on the event receipt, including: Write a pre-occupancy record for each controlled access resource in the target resource sequence, and associate the pre-occupancy record with the vehicle identifier and the entry sequence marker; When both the entry receipt and the occupancy confirmation are satisfied in the event receipt, the corresponding controlled access resource will be transferred from the pre-occupancy state to the occupancy state, and other pre-occupancy records of the same controlled access resource will be cleared. When both the exit receipt and the idle confirmation are satisfied in the event receipt, the corresponding controlled access resource will be transferred from the occupied state to the idle state. When the permit timeout flag corresponding to the permit waiting timer arrives, the pre-occupancy record in the target resource sequence is revoked and the corresponding controlled access resource is restored to an idle state. The interlock management module outputs permission determination results based on the interlock condition set, resource status table, and pre-occupancy record. The permission determination results include access flags and blocking reason codes.

[0010] Furthermore, the rollback recovery module constructs waiting dependencies and identifies circular wait flags based on waiting instructions, pre-emptive states, and resource state mechanisms, including: The waiting resource identifier is determined based on the blocking reason code carried by the waiting instruction, and a waiting edge is established between the vehicle identifier and the waiting resource identifier; The occupying vehicle identifier is determined based on the pre-occupancy record and occupancy status in the resource status table, and the waiting edge is connected to the occupying vehicle identifier to form a dependency edge; When a closed loop is formed by the dependent edges, a circular wait flag is generated, and a freeze permit issuance instruction is output to the permit scheduling module. The set of candidate vehicles for backoff is determined based on the cyclic waiting flag. The set of candidate vehicles for backoff includes vehicle identifiers that occupy bottleneck-controlled passage resources and have a backoff point flag. The loop wait flag and the set of candidate vehicles for rollback are output for rollback sequence generation.

[0011] Furthermore, the rollback recovery module sends a rollback sequence to the selected vehicle. The rollback sequence includes a rollback path, rollback point confirmation, resource release, and control segment reconnection, including: Issue a speed limit action to the selected vehicle and initiate a yielding permission application, which includes the yielding path and yielding point markings. After the interlock management module outputs an access mark for the yield permission application, it issues a yield execution command to drive the vehicle along the yield path to the yield point, and collects the yield point confirmation and writes it into the event receipt. When the event receipt detects that the yield point has been reached, the pre-occupancy record corresponding to the selected vehicle is cancelled and the occupancy status is transferred to the idle status, generating a resource release receipt. After the resource release receipt arrives, a control segment reattachment instruction is output to the permit scheduling module to bind the selected vehicle back to the control segment to be entered in the original control segment sequence, and the frozen passage permit issuance instruction is released.

[0012] Furthermore, the rollback recovery module triggers rollback sequence generation and performs resource release when the permission timeout flag arrives, including: Receive the license timeout flag output by the license scheduling module, and determine the corresponding vehicle identifier and target resource sequence based on the license timeout flag; Add the corresponding vehicle identifier to the rollback candidate vehicle set, and mark the pre-occupancy record in the target resource sequence as timed-out pre-occupancy; Output a freeze permit issuance instruction to the permit scheduling module and determine the selected vehicle based on the timeout pre-occupancy; Generate a reversal sequence for the selected vehicle and issue a reversal execution command to enable the selected vehicle to drive along the reversal path into the reversal point to complete the reversal point confirmation; After confirming arrival at the yield point, the timeout pre-occupancy is revoked and a resource release receipt is generated. A control segment reattachment instruction is then sent to the permit scheduling module to resume the permit application process.

[0013] Furthermore, the safety linkage module triggers an operating mode switch based on personnel detection signals or emergency stop signals and injects incremental interlock rules into the interlock management module, including: When a personnel detection signal or emergency stop signal arrives, a restricted mode flag is generated, and a permission restriction instruction is output to the permission scheduling module to restrict the issuance of passage permits; The set of affected controlled access resources is determined based on the restricted mode marker, and interlock incremental rules are issued to the interlock management module to put the affected controlled access resources into a blocked state. Speed ​​limit and traffic restriction policies are issued to affected vehicles, and execution receipts are collected and written into event receipts; The interlock management module outputs the blocking reason code for the access permit application based on the blocking status and maintains the interlock condition set update result.

[0014] Furthermore, the security linkage module issues a progressive recovery command based on the security deactivation receipt to restore the application for and issuance of the pass permit, including: Receive the security release receipt and generate a release confirmation flag, and issue the interlock release rule to the interlock management module to transfer the affected controlled access resources from the blocked state to the pre-occupied state; Output phased recovery instructions to the permit scheduling module so that the access permits are restored and issued in sequence according to the priority of the controlled access resources, and collect occupancy confirmation and idle confirmation to update the resource status table in each phase; During the phased recovery command execution, the speed limit policy is maintained until the resource release receipt of the affected controlled traffic resources reaches the preset stability condition. Once the stability conditions are met, the speed limit policy is lifted and the license restriction instruction is revoked, completing the switch from the restricted mode flag to the normal mode flag.

[0015] The technical effects and advantages of the AGV production line intelligent scheduling and optimization system of this invention are as follows: This invention achieves coordinated optimization of AGV production line task execution and traffic control by constructing a closed-loop control system that integrates state aggregation, interlock management, permission scheduling, rollback recovery, and safety linkage. Under a unified time reference, the system aggregates task requests, vehicle status, and roadside occupancy and idle confirmations to form status frames and event receipts, providing consistent input for interlock determination. The interlock management module establishes a mutual exclusion table and interlock condition set with controlled traffic resources as the boundary, and introduces a dual confirmation triggering mechanism of pre-occupancy registration and entry receipt occupancy confirmation, and exit receipt idle confirmation to avoid erroneous occupancy and release caused by relying on only one side of information, thus suppressing the preemptive conflict at narrow channels and intersections from the source. The permit scheduling module divides the task path into control segment sequences and completes the permit application and waiting timer before entry, enabling vehicles to enter bottleneck resources in a controlled manner and reducing congestion spread. The backoff recovery module identifies cyclic waiting or permit timeout based on waiting dependencies and freezes permit issuance. It issues a backoff sequence to selected vehicles, including backoff path, backoff point confirmation, resource release, and control segment reconnection, achieving self-recovery from congestion and deadlock. The safety linkage module injects personnel detection and emergency stop constraints into the scheduling link with interlocked incremental rules and permit restriction instructions, and smoothly restores passage through gradual recovery instructions, avoiding secondary risks caused by concentrated rushing at the moment of release. This improves the stability of passage, scheduling continuity, and operational controllability of the production line in scenarios with multiple vehicles running concurrently, channel conflicts, and safety interventions. Attached Figure Description

[0016] Figure 1 This is a schematic diagram of the AGV production line intelligent scheduling and optimization system of the present invention. Detailed Implementation

[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0018] In order to achieve the above objectives, Figure 1 A structural diagram of the intelligent scheduling and optimization system for AGV production lines of the present invention is provided, which specifically includes a status aggregation module, an interlock management module, a permission scheduling module, a rollback and recovery module, and a safety linkage module. The modules are connected through data communication. The status aggregation module is used to receive task requests, vehicle status, roadside occupancy confirmations and vacancy confirmations, and generate status frames and event receipts. The interlock management module is used to determine the controlled access resources based on the status frame and establish a mutual exclusion table, generate an interlock condition set and resource state machine, register the pre-occupancy status of the target resource sequence carried by the access permit application, and trigger the transition from the pre-occupancy status to the occupancy status with the entry receipt and occupancy confirmation, and trigger the transition from the occupancy status to the idle status with the exit receipt and idle confirmation. The permit scheduling module is used to generate a task pool and divide the control segment according to the controlled access resource boundary. Before the vehicle enters the control segment, it initiates a pass permit application to the interlock management module, records the permit waiting time and outputs the permit timeout flag, and issues a pass permit order or waiting instruction according to the permit result. The rollback recovery module is used to construct waiting dependencies based on waiting instructions, pre-occupancy status and resource state mechanism, identify cyclic waiting flags or permission timeout flags, freeze the passage permission issuance instructions and issue rollback sequences to selected vehicles. The rollback sequence includes a retreat path, retreat point confirmation, resource release and control segment reconnection. The safety linkage module is used to trigger the switching of operating modes and issue speed limit and prohibition policies based on personnel detection signals or emergency stop signals, inject interlock incremental rules into the interlock management module and issue permission restriction instructions to the permission scheduling module, and issue progressive recovery instructions based on safety release receipts.

[0019] The status aggregation module is used to receive task requests, vehicle status, roadside occupancy confirmations, and idle confirmations, and to generate status frames and event receipts. Specific implementation details include: The status aggregation module serves as the unified input port for the production line scheduling and control chain. It establishes data communication connections with the upper-level task issuing end, vehicle-side communication unit, and roadside detection end communication unit. It is used to access task requests, vehicle status, roadside occupancy confirmations, and idle confirmations under a unified time reference, forming status frames and event receipts that can be directly used by the interlock management module and the permission scheduling module.

[0020] The task request is output by the upper-level task issuing terminal. After receiving the task request, the status aggregation module extracts the task identifier, start identifier, end identifier and priority flag from the task request, and writes the task identifier into the task record entry. Simultaneously, the vehicle identifier set is obtained based on the registry of the vehicle-side communication unit, and the task record entries are associated with the vehicle identifiers. The association method is to write the target vehicle identifier or the candidate vehicle identifier list into the task record entries. The candidate vehicle identifier list is generated by the range of executable vehicles given by the upper-level task issuing end or by the set of available vehicles returned by the vehicle-side communication unit, so that executable vehicles can be located according to the association when generating the task pool.

[0021] The vehicle status is reported periodically by the vehicle-end communication unit or triggered by an event. The status aggregation module extracts the pose marker, cargo marker, task stage marker and fault marker for each vehicle status and forms a vehicle status subframe. The pose marker is used to represent the vehicle's position and orientation in the factory map coordinate system. The position is output by the vehicle navigation and positioning unit and encapsulated and reported by the vehicle-end communication unit. The orientation is given by the vehicle heading angle or attitude calculation result. The cargo loading marker indicates whether the vehicle is in a cargo loading state and is output by the vehicle's fork sensors, pallet detection switches, or vehicle identification unit; the task stage marker indicates whether the vehicle is currently in the stage of picking up, transporting, delivering, waiting, or returning to charging and is output by the vehicle's task execution state machine. Fault markers are used to indicate whether the vehicle has experienced an emergency stop, drive malfunction, communication malfunction, or positioning malfunction. They are output by the vehicle self-test unit and form standard fault codes in the vehicle's communication unit.

[0022] Roadside occupancy and vacancy confirmations are reported by the roadside detection terminal communication unit. The roadside detection terminal is deployed at the entry point, exit point, or key location inside the controlled traffic resource area to confirm vehicle entry into, occupation of, and release of the resource. After receiving roadside occupancy confirmation and idle confirmation, the status aggregation module extracts the resource identifier and confirmation type flag to form a roadside status subframe. The resource identifier is used to uniquely identify the controlled passage resource, and the confirmation type flag is used to distinguish between occupancy confirmation and idle confirmation. Occupancy confirmation is output by the roadside detection end when it detects that the resource is occupied by a vehicle, and idle confirmation is output by the roadside detection end when it detects that the resource has returned to idle. The roadside detection end can use geomagnetic detection, photoelectric beam, laser scanning or video area occupancy determination to realize occupancy detection. However, regardless of the detection method used, the resource identifier and confirmation type flag must be carried in the output to maintain interface consistency.

[0023] The state aggregation module performs unified time base alignment on vehicle state subframes and roadside state subframes and encapsulates them into state frames.

[0024] Specifically, the status aggregation module adds a receiving time stamp to each piece of access data. The receiving time stamp is generated using a unified clock within the controller. When the vehicle-side communication unit or the roadside detection unit provides a sending time stamp, the status aggregation module saves both the sending time stamp and the receiving time stamp for consistency verification. Subsequently, the status aggregation module splices the vehicle status subframe corresponding to the same vehicle identifier with the latest roadside status subframe in the alignment window within the preset alignment window, generating a status frame containing task record entry index, vehicle identifier, pose marker, cargo marker, task stage marker, fault marker, resource marker and confirmation type marker, and outputs the status frame to the interlock management module and the permit scheduling module.

[0025] The meaning of the alignment window is to allow multiple source data to have different arrival times in a short period of time, but to treat them as inputs of the same control cycle within the window. The size of the alignment window is determined by the controller's sampling period and communication delay budget. In the embodiment, the window size is set by configuration parameters so that the same alignment strategy can be reproduced under different network conditions.

[0026] While generating the status frame, an event receipt is further generated to pair the vehicle-side entry receipt and exit receipt with the roadside occupancy confirmation and idle confirmation according to the vehicle identifier and resource identifier, so as to support the resource state machine of the interlock management module to perform dual confirmation triggering.

[0027] Specifically, the status aggregation module receives vehicle entry receipts and vehicle exit receipts from the vehicle-side communication unit. The vehicle entry receipt indicates that the vehicle has arrived at the entry point of a controlled access resource and is preparing to enter or has already entered the controlled access resource. The vehicle exit receipt indicates that the vehicle has arrived at the exit point of the controlled access resource and has completed the exit. Both vehicle entry and exit receipts carry vehicle and resource identifiers, as well as a receipt timestamp. The status aggregation module pairs vehicle entry receipts with occupancy confirmations for the same resource identifier and vehicle exit receipts with idle confirmations for the same resource identifier. The pairing rule is to prioritize the pair of receipts with the closest timestamps within the alignment window as a pairing result. If the same vehicle identifier repeatedly reports entry or exit receipts for the same resource identifier, the latest receipt overwrites the old receipt and the number of overwrites is recorded. If a vehicle entry receipt is present but lacks an occupation confirmation, or a vehicle exit receipt is present but lacks an idle confirmation, the incomplete pairing receipt is recorded as a pending pairing receipt and continues to wait for subsequent roadside confirmations. The status aggregation module encapsulates the pairing results into event receipts. Each event receipt includes at least a vehicle identifier, resource identifier, entry receipt, exit receipt, occupation confirmation, idle confirmation, and receipt timestamp. The event receipts are then output to the interlock management module and the permit scheduling module. This allows the interlock management module to use the arrival of both the entry receipt and occupation confirmation as the trigger condition for a resource to transition from a pre-occupied state to an occupied state, and the arrival of both the exit receipt and idle confirmation as the trigger condition for a resource to transition from an occupied state to an idle state. Simultaneously, the permit scheduling module can determine whether a vehicle has entered the control segment and whether it has released resources based on the event receipts, and advance the control segment execution accordingly.

[0028] The status aggregation module can index and store pending pairing receipts by vehicle identifier and resource identifier, so that the pairing process can be used under multi-vehicle concurrency and network jitter conditions. Specifically, the status aggregation module writes a receipt time stamp and a receipt type stamp for each pending pairing receipt and puts it into the pending pairing queue. The pending pairing queue uses the vehicle identifier and resource identifier as a composite key to ensure that entry or exit receipts of the same vehicle identifier on the same resource identifier can be overwritten and updated, and records the number of overwrites. The status aggregation module scans the pairing queue in each control cycle. When it detects that an occupancy confirmation or idle confirmation with the same resource identifier has arrived, it prioritizes pairing with the receipt with the closest timestamp in the pairing queue and generates an event receipt. When a pending pairing receipt fails to complete pairing outside the alignment window, the state aggregation module marks the receipt as timed out and writes an exception flag in the status frame. At the same time, it outputs an exception prompt to the interlock management module to avoid erroneously triggering the resource state machine transition, and outputs an exception prompt to the permit scheduling module to avoid issuing new passage permits to the relevant vehicles. Through the index storage of the pending pairing queue and the timeout exception output, the state aggregation module can maintain the traceability and consistency of event receipt generation when receipts are missing, out of order, or delayed by roadside detection.

[0029] Further specify the handling methods for missing data and abnormal situations: When the vehicle status is not updated within several consecutive control cycles, the status aggregation module sets the vehicle's fault flag to communication abnormal and retains the most recent valid pose flag. At the same time, it writes the abnormal flag into the status frame so that the permission scheduling module can avoid issuing a new passage permission order to the vehicle. When the roadside occupancy confirmation and vacancy confirmation are not updated within several consecutive control cycles, the status aggregation module sets the confirmation type flag of the corresponding resource identifier to unknown and writes an exception flag in the status frame, so that the interlock management module can determine the controlled access resource as unaccessible in the interlock condition set. When the pairing results of the entry receipt and the occupation confirmation or the exit receipt and the idle confirmation show inconsistencies in vehicle identification or differences in time stamps exceeding the alignment window, the state aggregation module marks the pairing result as an invalid pairing and records it as an event awaiting manual review. At the same time, it outputs the result to the interlock management module to avoid triggering erroneous resource state machine transitions.

[0030] Through the aforementioned state frame generation, event receipt pairing, and exception handling process, the state aggregation module achieves unified aggregation and consistent output of task requests, vehicle status, and roadside confirmations, providing an input basis for the interlock condition set determination and resource state machine driving of the interlock management module, as well as the control segment permission application and execution advancement of the permission scheduling module.

[0031] The interlock management module is used to determine controlled access resources based on status frames and establish a mutual exclusion table, generate an interlock condition set and resource state machine, register the pre-occupancy status of the target resource sequence carried in the access permit application, and trigger the transition from the pre-occupancy status to the occupied status with the entry receipt and occupancy confirmation, and trigger the transition from the occupied status to the idle status with the exit receipt and idle confirmation. Specific implementation details include: The interlock management module establishes data communication connections with the status aggregation module and the permit scheduling module. It receives status frames and event receipts output by the status aggregation module, determines the controlled access resources based on the status frames and establishes a mutual exclusion table, generates an interlock condition set, a resource state machine and a resource state table, and performs interlock verification and pre-occupancy registration on the access permit application initiated by the permit scheduling module. At the same time, the interlock management module drives the resource state machine to complete the state transition between idle state, pre-occupancy state and occupied state based on the event receipts, thereby providing an executable interlock constraint basis for the issuance of access permits.

[0032] For ease of understanding, controlled access resources can be understood as shared passage units within the production line that require access control, such as narrow passages, intersections, buffer zones before the entrances and exits of automated warehouses, and single-vehicle passing areas at workstation entrances. In actual factories, these areas often experience oncoming traffic, entrance grabbing, and queuing congestion, thus requiring an interlock management module to control their mutual exclusion.

[0033] After receiving the status frame, the interlock management module first determines the set of controlled passage resources based on the resource identifiers in the roadside status subframe.

[0034] Specifically, the interlock management module maintains a resource configuration table, which records the spatial range, entry point marker, exit point marker, yield point marker, and backoff point marker corresponding to each resource identifier. When a new resource identifier appears in the status frame and is not in the resource configuration table, the interlock management module adds the resource identifier to the controlled access resource set and triggers the configuration loading process. The configuration loading process can be completed by importing from the project configuration file or by writing the configuration from the operation and maintenance end, so as to ensure that the determination of the controlled access resource set has a reproducible source.

[0035] Entry point markers are used to indicate the determination point where a vehicle enters a controlled access resource, and exit point markers are used to indicate the determination point where a vehicle exits a controlled access resource. In practical applications, entry point markers and exit point markers can correspond to the detection positions deployed by roadside detection terminals at the resource entrance and exit, or they can correspond to virtual threshold lines on the map. However, they must all correspond one-to-one with resource identifiers to ensure that subsequent entry receipts, exit receipts, occupation confirmations, and vacancy confirmations can be consistently associated with resource identifiers.

[0036] After obtaining the set of controlled access resources, the interlock management module generates a mutex table based on the set of controlled access resources, the specific contents of which include: The mutual exclusion table is used to record resource mutual exclusion pairs and mutual exclusion direction markers. Resource mutual exclusion pairs are used to represent that two controlled access resources cannot be occupied at the same time or can not be occupied by vehicles in the same direction at the same time. Mutual exclusion direction markers are used to represent the directional constraints of the mutual exclusion relationship.

[0037] The interlock management module uses mutual exclusion direction markers to perform directional verification of mutual exclusion occupancy conditions, in order to avoid the constraint problem of simultaneous operation in the same direction but not in opposite directions at intersections and narrow passages. Specifically, after receiving a passage permit application, the interlock management module determines the driving direction marker of the requesting vehicle on each resource identifier based on the target resource sequence carried in the passage permit application and the entry point marker and exit point marker in the resource configuration table. The driving direction marker is determined by reading the pose marker of the vehicle identifier in the status frame and combining it with the spatial orientation of the entry point marker and exit point marker corresponding to the adjacent resource identifier in the target resource sequence to obtain the direction of arrival and departure when the vehicle enters the resource identifier, thereby forming a direction expression that can be compared with the mutual exclusion direction marker. The interlock management module then locates the resource mutual exclusion pair related to the target resource sequence in the mutual exclusion table and matches the driving direction marker with the mutual exclusion direction marker. When the matching result indicates that the direction combination belongs to the mutual exclusion conflict direction, the mutual exclusion occupancy condition is determined to be unsatisfactory and the blocking reason code is output. When the matching result indicates that the direction combination belongs to the allowed concurrent direction, the mutual exclusion occupancy condition is determined to be unsatisfactory only when the resource is in an occupied state or there is a pre-occupancy record of another vehicle.

[0038] For example, in a narrow passage scenario, the narrow passage itself is a controlled passage resource, and the entrance areas at both ends of the narrow passage can be two adjacent controlled passage resources. A mutual exclusion table can be used to establish resource mutual exclusion pairs for the narrow passage and the entrance areas at both ends, and the mutual exclusion direction marker can be configured as one-way passage, so that only vehicles from one direction are allowed to enter the narrow passage at the same time. In an intersection scenario, the conflict area of ​​the intersection is a controlled passage resource, and the entry segments from different directions are adjacent controlled passage resources. The mutual exclusion direction marker is used to distinguish between direction combinations that can pass concurrently and direction combinations that cannot pass concurrently. The mutual exclusion table can be generated in two ways: First, it can be pre-configured in the project, where a list of conflicting resource identifiers and conflict direction markers for each resource identifier are pre-stored in the resource configuration table, and the interlock management module automatically generates the mutual exclusion table after loading the resource configuration table. Second, it can be generated using topology deduction, where the interlock management module determines spatial overlap or passage conflicts based on the spatial range and connectivity of each resource in the resource configuration table, and writes the conflicting resource pairs into the mutual exclusion table. Regardless of the method used, the mutual exclusion table uses the resource identifier as the primary key and the resource mutual exclusion pairs and mutual exclusion direction markers as its content, enabling the permission scheduling module and the rollback recovery module to reference mutual exclusion relationships using a unified identifier.

[0039] The interlock management module automatically generates a mutual exclusion table using a reproducible topology derivation process. Specifically, this includes: the interlock management module reading the spatial range and connectivity of each resource identifier from the resource configuration table, expressing the spatial range as a sequence of boundary points in the plant's map coordinate system, and forming a region boundary that can be used for intersection and overlap determination; the interlock management module performing region relationship determination on any two resource identifiers, and registering the resource identifier pair as a resource mutual exclusion pair when the two region boundaries overlap, intersect, or share a conflict zone entrance; furthermore, the interlock management module, based on connectivity and entry point markers, ... The exit point marker derives possible combinations of vehicle travel directions. When two resource identifiers' travel direction combinations cross or meet in opposite directions within the intersection conflict zone, the interlock management module writes a mutual exclusion direction marker for the resource mutual exclusion pair. When two resource identifiers only merge in the same direction or follow each other without causing a conflict zone intersection, the interlock management module writes a mutual exclusion direction marker that allows concurrency for the resource mutual exclusion pair. The interlock management module writes the derived resource mutual exclusion pair and mutual exclusion direction marker into the mutual exclusion table and outputs it to the interlock condition set generation process, so that subsequent mutual exclusion occupancy conditions can directly reference the mutual exclusion table to complete the permission determination.

[0040] The interlock management module further generates an interlock condition set based on the mutex table and state frame, and establishes a resource state machine, including the following: The interlock condition set is used to determine the access permission application. In the embodiment, the interlock condition set includes mutual exclusion occupancy condition, closed access prohibition condition, and buffer capacity condition.

[0041] The mutual exclusion occupancy condition is determined based on the mutual exclusion table. When any resource identifier in the target resource sequence carried in the passage permit application is in an occupied state or its mutually exclusive resource identifier is in an occupied state, the mutual exclusion occupancy condition is determined to be unsatisfied. When there is a pre-occupancy record in the target resource sequence and the vehicle identifier associated with the pre-occupancy record is inconsistent with the applicant vehicle identifier, the mutual exclusion occupancy condition is determined to be unsatisfied.

[0042] The closure and access restriction conditions are determined based on the roadside status subframe in the status frame. When the roadside status subframe indicates that the resource identifier is in the closure and access restriction state or the interlock management module receives an interlock incremental rule injected by the safety linkage module that causes the resource identifier to enter the blocked state, the closure and access restriction conditions are determined to be unmet. The closed and restricted status can be generated by manual road closure signals, access control lock signals, or security protection zone trigger signals. The interlock management module converts these signals into a unified blockage marker for resource identification and writes it into the resource status table.

[0043] The buffer capacity condition is used to constrain the number of controlled access resources entering the buffer. When the buffer capacity limit is configured for the resource identifier in the resource configuration table and the current number of occupied vehicles reaches the buffer capacity limit, the buffer capacity condition is determined to be unsatisfactory. The number of occupied vehicles is obtained by counting the occupancy records in the resource status table. The occupancy records are synchronously written when the resource state machine transition is triggered by the event receipt.

[0044] The resource state machine is used to maintain three states: idle, reserved, and occupied. The idle state indicates that the resource has no reserved or occupied records. The reserved state indicates that the resource has a reserved record but has not yet met the double confirmation conditions of entry receipt and occupation confirmation. The occupied state indicates that the resource meets the double confirmation conditions of entry receipt and occupation confirmation and has been written into the occupation record. The resource status table records the current status, pre-occupied record set, occupied record set, lock flag, and buffer capacity limit of each resource identifier to support the determination and output of interlock condition sets.

[0045] When the permit scheduling module initiates a passage permit application for the control segment to be entered, the interlock management module receives the passage permit application and performs pre-occupancy registration and permit determination. The passage permit application carries the vehicle identifier, target resource sequence and entry order mark. The target resource sequence is a list of resource identifiers arranged in the entry order, and the entry order mark is used to identify the order in which vehicles occupy the target resource sequence.

[0046] The interlock management module performs interlock condition set verification on each target resource sequence. When the verification passes, it writes each resource identifier in the target resource sequence into the pre-occupancy record. The pre-occupancy record is associated with the vehicle identifier and the entry order mark, and the resource state machine of the corresponding resource identifier is set to the pre-occupancy state. When the verification fails, the interlock management module outputs the permission judgment result as prohibited and writes the blocking reason code into the permission judgment result. The blocking reason code is used to indicate three specific reasons: mutual exclusion, closed entry prohibition, or buffer capacity. This allows the permission scheduling module to generate waiting instructions and the rollback recovery module to build waiting dependencies.

[0047] It should be noted that, in order to avoid the expansion of the pre-occupancy record due to repeated applications for the same vehicle, the interlock management module first queries the resource status table before writing the pre-occupancy record. If the vehicle identifier already has a pre-occupancy record on the same resource identifier, the entry order flag and registration time flag of the pre-occupancy record are updated without adding a new record. If there are pre-occupancy records for other vehicle identifiers and the interlock condition set allows queuing pre-occupancy, the pre-occupancy records are sorted according to the entry order flag and the queuing flag is written into the permission determination result. However, in this embodiment, in order to ensure that the mutual exclusion occupancy condition is clear, queuing pre-occupancy can be configured to not be allowed, so that the pre-occupancy status has the determinism of single-vehicle occupancy.

[0048] After completing the pre-occupancy registration, the interlock management module drives the resource state machine to complete the state transition based on event receipts, so as to realize a double confirmation closed loop of pre-occupancy and occupancy.

[0049] Specifically, the interlock management module continuously receives event receipts output by the status aggregation module. When both the entry receipt and the occupancy confirmation are satisfied in the event receipt, the corresponding resource identifier is transferred from the pre-occupancy state to the occupancy state and written into the occupancy record. At the same time, the pre-occupancy records of other vehicle identifiers on the same resource identifier are cleared. The entry receipt is used to indicate that the vehicle has entered the resource entrance or the interior of the resource, and the vehicle identifier carried in the entry receipt is consistent with the vehicle identifier associated with the pre-occupancy record. The occupancy confirmation is used to indicate that the roadside detection end determines that the resource space range has been occupied by a vehicle, and the resource identifier carried in the occupancy confirmation is consistent with the resource identifier in the target resource sequence. The state transition is only allowed when both conditions are met, thereby avoiding misjudgments caused by relying solely on vehicle receipts or solely on roadside confirmations.

[0050] When the interlock management module detects that both the exit receipt and the idle confirmation are satisfied in the event receipt, it will change the corresponding resource identifier from occupied to idle and clear the occupation record. The exit receipt indicates that the vehicle has left the resource exit or has reached the exit point marker, and the idle confirmation indicates that the roadside detection terminal determines that the resource space range has been restored to idle. Release is only allowed when both conditions are met, thereby avoiding the erroneous release of resources caused by the early arrival of the vehicle exit receipt or the delayed arrival of the roadside idle confirmation.

[0051] To accommodate the license waiting timer mechanism of the license scheduling module, the interlock management module also performs pre-emption cancellation processing when it receives a license timeout flag or detects a pre-emption timeout event internally.

[0052] Specifically, when the permission timeout flag output by the permission scheduling module arrives and the permission timeout flag is associated with a vehicle identifier and a target resource sequence, the interlock management module cancels the pre-occupancy record in the target resource sequence and restores the corresponding resource identifier to an idle state. During cancellation, only the pre-occupancy record that is in a pre-occupancy state and whose associated vehicle identifier matches is canceled, so as to avoid affecting the resources that have already entered the occupied state. At the same time, the interlock management module updates the resource status table and outputs the blocking reason code of the permission determination result to the permission scheduling module as timeout recycling, so that the permission scheduling module and the rollback recovery module can further trigger the rollback sequence.

[0053] Through the above-mentioned determination of the controlled access resource set, generation of the mutual exclusion table, construction of the interlock condition set and resource state mechanism, registration of the target resource sequence pre-occupancy, and processing of double-confirmation state transition and pre-occupancy cancellation, the interlock management module can achieve executable interlock control in actual production line narrow passages, intersections, warehouse buffer zones, and other scenarios. This ensures that access permit applications, access permit orders, waiting instructions, and rollback sequences operate in a closed loop under the same resource identification system and the same state machine semantics, thereby enabling the permit scheduling module to advance the control segment and the rollback recovery module to perform cyclic waiting and self-recovery.

[0054] The permit scheduling module is used to generate a task pool and divide the control segment according to the controlled access resource boundary. Before a vehicle enters the control segment, it initiates a passage permit application to the interlock management module, records the permit waiting time and outputs a permit timeout flag, and issues a passage permit order or waiting instruction based on the permit result. Specific implementation details include: The permission scheduling module establishes data communication connections with the status aggregation module, interlock management module, and rollback recovery module. It receives status frames and event receipts output by the status aggregation module, receives permission determination results output by the interlock management module, and aggregates task requests output by the upper-level task issuing terminal to generate a task pool. The permission scheduling module further divides the task path into a control segment sequence based on the controlled access resource boundary. Before the vehicle enters the control segment, it initiates a passage permission application to the interlock management module, records the permission waiting time and outputs a permission timeout flag, and issues a passage permission order or waiting instruction to the vehicle terminal according to the permission determination result. This enables the task dispatch and access control within the AGV production line to be executed in a closed loop within the same sequence control chain, thereby achieving synchronous optimization of production line scheduling and congestion suppression.

[0055] Regarding task pool generation, the permit scheduling module periodically receives task requests and creates task pool entries. Each task pool entry contains at least a task identifier, a start identifier, an end identifier, a priority flag, and vehicle identifier information associated with the task. The vehicle identification information comes from the association established between the task request and the vehicle identification by the status aggregation module. Based on this, the permission scheduling module determines the set of executable vehicles and filters out unexecutable vehicles by combining the fault flags and task stage flags in the status frame.

[0056] The permission scheduling module maintains a task pool status field to mark the pending, executing, paused, and completed status of task pool entries. When a task is assigned to a vehicle identifier, the permission scheduling module writes the executing vehicle identifier of the task pool entry and updates the task pool status field to executing. At the same time, it updates the task stage mark of the vehicle identifier to the corresponding stage of pickup, transportation, or delivery to ensure that the task pool and vehicle execution status are consistent.

[0057] In actual production line scenarios, task requests in the embodiment can come from workstation call buttons, warehouse entry / exit instructions, or handling instructions issued by the upper-level manufacturing execution system. The permission scheduling module encapsulates task requests from different sources into task pool entries using a unified field, so that the scheduling logic does not depend on the differences in task sources.

[0058] In terms of control segment segmentation, the permission scheduling module, based on the set of controlled access resources and resource configuration table provided by the interlock management module, decomposes the task path into a sequence of control segments arranged in the execution order.

[0059] Specifically, the permission scheduling module first generates a candidate path on the plant map topology based on the starting point identifier and the ending point identifier. The candidate path consists of continuous path nodes, and each path node is mapped to a map segment or a controlled access resource. Subsequently, the permission scheduling module uses the entry and exit point markers of the controlled access resources as the dividing boundaries to divide the candidate path into multiple control segments, so that each control segment corresponds to a continuous driving path and is closed by the controlled access resource boundary.

[0060] For each control segment, the permission scheduling module binds the target resource sequence and the alternative yield point marker. The target resource sequence is a list of controlled access resource identifiers that vehicles need to enter in sequence within the control segment. The alternative yield point marker is used to guide vehicles to a designated waiting position when permission is prohibited or congestion occurs. Alternate yield point markers can be pre-configured using a resource allocation table. For example, yield points can be set outside narrow passage entrances, before intersections, and before automated parking garage entrances. Through this control segment segmentation method, the permit scheduling module transforms task execution from continuous path planning into segmented execution within controlled traffic resource boundaries. This allows permit applications and resource pre-allocation to be completed before entering the control segment, thereby reducing the probability of conflicts occurring after vehicles enter the bottleneck area.

[0061] Regarding permit application and permit waiting time, the permit scheduling module generates a permit application for the control segment to be entered and initiates it to the interlock management module. The permit application carries a vehicle identifier, a target resource sequence, and an entry order flag. The entry order flag indicates the order in which vehicles occupy the target resource sequence. The permit scheduling module writes the corresponding entry order flag for each resource identifier according to the order of the target resource sequence. After the permit application is initiated, the permit scheduling module starts a permit waiting timer for the vehicle identifier and the target resource sequence. The start time of the permit waiting timer is the initiation time of the permit application, and the permit waiting timer is implemented by a unified clock within the controller. The permit scheduling module increments and updates the permit waiting timer in each control cycle and writes the current permit waiting timer into the waiting context record. The waiting context record contains at least the vehicle identifier, the target resource sequence, the blocking reason code, and the permit waiting timer. If the interlock management module returns a permission determination result of prohibition, the permission scheduling module generates a waiting instruction based on the blocking reason code in the permission determination result and sends it to the vehicle. The waiting instruction carries the vehicle identifier, the alternative yield point marker and the blocking reason code. The vehicle stops and waits at the alternative yield point or maintains its formation at a low speed. During the waiting period, the permission scheduling module keeps the permission waiting time incremented and periodically resends the passage permission application so that the passage permission order can be obtained in a timely manner after the interlock conditions are met.

[0062] If the permission waiting time reaches the preset time limit, the permission scheduling module generates a permission timeout flag and outputs it to the rollback recovery module. The permission timeout flag includes at least the vehicle identifier, the target resource sequence, and the timeout time flag, which is used to trigger the generation of subsequent rollback sequences and the pre-occupancy cancellation process. The preset time limit is a configurable parameter that can be configured by production line operation and maintenance according to the channel length and the normal passage time to adapt to different factory layouts.

[0063] Regarding issuing passage permits or waiting instructions based on the permit results, the permit scheduling module receives the permit determination results output by the interlock management module and executes the instruction issuance. The permit determination results include an access flag and a blocking reason code. When the access flag indicates that the permit is allowed, the permit scheduling module issues a passage permit to the vehicle. The passage permit includes at least the vehicle identifier, target resource sequence, entry sequence flag, and target control segment flag. After receiving the passage permit, the vehicle enters the control segment execution state and enters the controlled access resources in the target resource sequence in sequence according to the entry sequence flag. When the access marker indicates that permission is prohibited, the permission scheduling module issues a waiting instruction along with a congestion reason code and an alternative yield point marker, causing the vehicle to wait in a controlled manner at the entrance of the control segment without entering the controlled passage resource. To ensure that the advancement of the control segment has a verifiable succession relationship, the permission scheduling module determines whether a vehicle has entered the control segment and whether it has completed the control segment based on event receipts: When the vehicle entry receipt and the occupation confirmation appear in the event receipt and are aligned to the first resource identifier in the target resource sequence, the permission scheduling module marks the control segment as being executed; When the vehicle exit receipt and idle confirmation in the event receipt are aligned with the last resource identifier in the target resource sequence and the task stage marker of the vehicle identifier meets the transportation segment advancement conditions, the permit scheduling module marks the control segment as completed and switches to the permit application process for the next control segment, thereby forming a closed-loop scheduling mechanism between control segments.

[0064] For example, in a scenario where multiple workstations are connected by a narrow aisle on an AGV production line, a vehicle needs to transport materials from the starting workstation to the ending workstation. The permission scheduling module adds the transport task to the task pool and generates a target resource sequence containing the narrow aisle resource identifier for the vehicle. When the narrow passage is occupied by another vehicle, the interlock management module returns a permission prohibition and outputs a blocking reason code as mutual exclusion. Based on this, the permission scheduling module issues a waiting instruction to guide the vehicle to stop at the yielding point outside the narrow passage entrance, and at the same time starts the permission waiting timer and continuously applies for permission. Once the vehicle has exited the restricted area and the roadside is confirmed to be clear, the interlock management module returns permission, and the permission dispatch module issues a passage permit to allow the vehicle to enter the narrow passage to complete the transport. If a vehicle malfunctions and obstructs the road, causing the permit waiting time to reach the preset limit, the permit scheduling module outputs a permit timeout flag to the rollback recovery module. This flag is used to freeze the issuance of permits and execute the rollback sequence, preventing multiple vehicles from continuously waiting and forming a loop.

[0065] Through the above-mentioned implementation methods of task pool generation, control segment segmentation, permit application and waiting timer, permit result-driven instruction issuance, and event receipt-driven control segment advancement, the permit scheduling module can achieve coordinated control of scheduling and passage interlock in the AGV production line intelligent scheduling and optimization system. It supports the rollback recovery module in handling cyclic waiting and permit timeout in a recoverable manner, and works with the permit restriction instructions of the safety linkage module to complete the gradual recovery in the restricted mode.

[0066] The rollback and recovery module is used to construct waiting dependencies based on waiting instructions, pre-occupancy status, and resource state mechanisms, identify circular wait flags or permission timeout flags, freeze passage permission issuance instructions, and issue rollback sequences to selected vehicles. The rollback sequence includes a retreat path, retreat point confirmation, resource release, and control segment reconnection. Specific implementation details include: The rollback and recovery module establishes a data communication connection with the status aggregation module, interlock management module, and license scheduling module. It is used to receive waiting instructions, license timeout flags, and context information of access license applications issued by the license scheduling module, receive resource status tables, pre-occupancy records, and occupancy status information output by the interlock management module, and receive status frames and event receipts output by the status aggregation module. Based on this, the rollback recovery module constructs waiting dependencies and identifies cyclic waiting flags or permission timeout flags. It outputs a freeze permission issuance instruction to the permission scheduling module to prevent new permission orders from entering the bottleneck area. At the same time, it selects vehicles and issues rollback sequences, enabling the production line to automatically yield, release key controlled traffic resources, and resume control segment advancement in typical scenarios such as oncoming traffic, intersection contention, and faulty vehicles occupying lanes. This achieves the self-recovery operation of the AGV production line intelligent scheduling and optimization system.

[0067] Regarding the construction of waiting dependencies, the rollback and recovery module establishes waiting edges with waiting instructions as the entry point and expands them based on the resource status table to form dependency edges. Specifically, each waiting instruction carries a vehicle identifier, a blocking reason code, and an alternative yield point marker. The rollback and recovery module reads the blocking reason code and determines the waiting resource identifier. The waiting resource identifier is the controlled passage resource identifier that prevents the vehicle from obtaining a passage permit. The waiting resource identifier is obtained either by the permit scheduling module simultaneously carrying the first unapproved resource identifier of the target resource sequence in the waiting instruction, or by the rollback and recovery module locating the corresponding resource identifier in the target resource sequence in combination with the blocking reason code in the permit determination result. Subsequently, the rollback and recovery module establishes a waiting edge, with the vehicle identifier as the starting point and the waiting resource identifier as the ending point, indicating that the vehicle identifier is waiting for the waiting resource identifier to be released or for the interlock condition to be met. The rollback and recovery module further reads the resource status table to query the occupancy status or pre-occupancy record corresponding to the waiting resource identifier. If the resource status table shows that the waiting resource identifier is in an occupied state, the occupying vehicle identifier is extracted and the waiting edge is connected to the occupying vehicle identifier to form a dependency edge, which indicates that the waiting vehicle is blocked by the occupied vehicle. If the resource status table shows that the waiting resource identifier is in a pre-reserved state and the vehicle identifier associated with the pre-reserved record is inconsistent with the waiting vehicle identifier, then the pre-reserved vehicle identifier is extracted and a dependency edge is formed. The dependency edge indicates that the waiting vehicle is blocked by the pre-reserved vehicle. Through the construction of the above waiting edge and dependency edge, the rollback recovery module aggregates the concurrent waiting of multiple vehicles in the field from scattered waiting instructions into analyzable waiting dependencies.

[0068] In terms of circular wait flag identification, the fallback recovery module performs closed-loop detection on the dependency edges, and generates a circular wait flag when the dependency edges form a closed loop. The loop closure detection is implemented by tracing the source of the blockage from the starting vehicle identifier of the dependent edge after each new dependent edge is added. If the tracing path returns to the starting vehicle identifier, it is determined that a loop has been formed and a loop waiting mark is generated. When generating a loop waiting flag, the rollback recovery module records the set of vehicle identifiers and the set of waiting resource identifiers involved in the closed loop, which serve as input for filtering the rollback candidate vehicle set.

[0069] It should be noted that, in order to ensure that closed-loop detection is not affected by instantaneous jitter, the rollback recovery module in this embodiment can only output a cyclic waiting flag when the same closed-loop candidate is established in multiple consecutive control cycles. The control cycle is a fixed system refresh cycle, which is uniformly configured by the controller. The meaning of "continuously established" is that the set of vehicle identifiers and the set of waiting resource identifiers involved in the closed loop remain unchanged or change within a preset tolerance range in multiple consecutive cycles. The preset tolerance range can be given by configuration parameters and used to filter out misjudgments caused by short-term communication delays.

[0070] Regarding the permission timeout flag processing, the rollback recovery module receives the permission timeout flag output by the permission scheduling module and determines the corresponding vehicle identifier and target resource sequence based on the permission timeout flag. The permission timeout flag carries the vehicle identifier, target resource sequence, and timeout time flag. The rollback recovery module adds the corresponding vehicle identifier to the rollback candidate vehicle set and marks the pre-occupancy records in the target resource sequence as timeout pre-occupancy to distinguish between normal pre-occupancy and timeout pre-occupancy. The meaning of timeout pre-occupancy is that the pre-occupancy record has not been able to complete the transition from pre-occupancy to occupied state through entry receipt and occupation confirmation after the permission waiting time has reached the preset time limit. Based on this, the rollback recovery module determines that the vehicle or the resource is in an abnormal blocking state and needs to trigger the rollback process to avoid the spread of waiting.

[0071] Regarding the freezing of permit issuance instructions, the rollback recovery module outputs a freezing permit issuance instruction to the permit scheduling module after generating a circular waiting flag or receiving a permit timeout flag. The freezing permit issuance instruction restricts the issuance of permits, preventing the permit scheduling module from issuing new permits to waiting resource identifiers or bottleneck-controlled traffic resources involved in the closed loop during the freeze period, thereby avoiding more vehicles entering the conflict area and expanding the closed loop range.

[0072] The instruction to freeze the passage permit issuance includes at least a freeze scope flag and a freeze trigger reason flag. The freeze scope flag is used to indicate the set of controlled passage resources or vehicle identifiers targeted by the freeze, and the freeze trigger reason flag is used to indicate whether the freeze is triggered by a loop wait flag or a permit timeout flag. The method for determining the freeze range marker is to include the set of waiting resource identifiers and the mutual exclusion resource identifiers in their mutual exclusion tables into the freeze range, in order to prevent the issuance of mutual exclusion resources and avoid secondary conflicts.

[0073] Regarding the determination of the rollback candidate vehicle set and the selected vehicle, the rollback recovery module determines the rollback candidate vehicle set based on the cyclic wait flag or timeout pre-occupancy, and selects the selected vehicle from the rollback candidate vehicle set.

[0074] The set of candidate vehicles for backing off includes vehicle identifiers that occupy bottleneck controlled passage resources and have a backoff point marker. The bottleneck controlled passage resources are controlled passage resources in the set of waiting resource identifiers that are depended on by multiple vehicles or located at a high conflict degree position in the mutual exclusion table. The high conflict degree position can be determined by the number of mutually exclusive pairs with the resource identifier in the mutual exclusion table. The more mutually exclusive pairs there are, the greater the impact of the resource identifier on the system passage.

[0075] The presence of a yield point marker means that the resource configuration table has configured a yield point marker for the resource where the vehicle is currently located or an adjacent resource, allowing the vehicle to exit its occupied position without creating a new mutual exclusion conflict. The selected vehicle is determined by prioritizing the vehicle identifier that is currently occupied and has the shortest yield path. The shortest yield path means the fewest number of path nodes or path segments from the vehicle's current position to the location corresponding to the yield point marker. Both the number of path nodes and path segments can be calculated from the plant's map topology. If no occupied vehicle is found in the candidate vehicle set, the vehicle corresponding to the timeout pre-occupancy or a vehicle with a later pre-occupancy order is selected to release critical resources.

[0076] Regarding the generation and distribution of rollback sequences, the rollback recovery module generates a rollback sequence for the selected vehicle and issues rollback execution instructions, specifically as follows: The rollback sequence includes the rollback path, rollback point confirmation, resource release and control segment reattachment. Specifically, the rollback recovery module first generates the rollback path, which is a sequence of path nodes from the current position of the selected vehicle to the corresponding position of the rollback point marker. The rollback path avoids resource identifiers corresponding to closed entry restrictions and occupied resource identifiers corresponding to mutual exclusion conditions. Subsequently, the rollback recovery module sends a rollback permission request to the interlock management module. The rollback permission request carries the rollback path and rollback point marker to ensure that the rollback action itself is also subject to the constraints of the interlock management module. After the interlock management module outputs the access mark, the rollback recovery module issues a rollback execution command to drive the vehicle along the rollback path and enter the rollback point. After the vehicle arrives at the rollback point, the vehicle-side communication unit reports the rollback point confirmation and writes it into the event receipt. When the rollback recovery module detects the arrival of the retreat point confirmation in the event receipt, it notifies the interlock management module to cancel the pre-occupancy record corresponding to the selected vehicle and triggers the transition from the occupied state to the idle state, generating a resource release receipt. The resource release receipt is used to indicate that the key controlled passage resources have been released. After the resource release receipt arrives, the rollback recovery module outputs a control segment reattachment instruction to the permit scheduling module, binding the selected vehicle back to the control segment to be entered in the original control segment sequence. This enables the permit scheduling module to resume the permit application process for the vehicle, while simultaneously unfreezing the permit issuance instruction or narrowing the freeze range mark, allowing production line traffic to gradually recover.

[0077] To illustrate with a practical example: On a production line, a narrow passage connects the raw material area and the workstation area at both ends. Two AGVs enter the narrow passage from opposite ends, preparing to pass in opposite directions. Vehicle A has already entered the narrow passage and is in a occupied state. Vehicle B receives a waiting instruction at the entrance and continues to apply for passage permission. At the same time, because Vehicle C needs to enter the workstation area at the other end of the narrow passage, it is blocked by Vehicle A. Vehicle A is also unable to exit because the buffer zone in front is full, resulting in a closed loop of waiting between Vehicle A, Vehicle B, and Vehicle C. The rollback and recovery module receives waiting instructions from vehicles B and C, constructs waiting edges, and forms dependent edges by combining them with the resource status table. After identifying the closed loop of dependent edges, it generates a cyclic waiting flag and outputs a freeze passage permit issuance instruction. Then, it selects vehicle A from the rollback candidate vehicle set, which has a yield point flag and the shortest yield path, as the selected vehicle. It issues a rollback sequence containing the yield path and yield point confirmation, causing vehicle A to roll back to the yield point outside the narrow passage entrance to complete the yield point confirmation. The interlock management module then generates a resource release receipt and turns the narrow passage into an idle state. After receiving the reconnection instruction from the control section, the permit scheduling module re-initiates a passage permit application for vehicle B and issues a passage permit order. Vehicle B enters the narrow passage to complete transportation, and the production line resumes normal operation.

[0078] The safety linkage module is used to trigger operation mode switching and issue speed limit and prohibition policies based on personnel detection signals or emergency stop signals. It also injects incremental interlock rules into the interlock management module and issues permission restriction instructions to the permission scheduling module. Based on safety release receipts, it issues progressive recovery instructions. Specific implementation details include: The safety linkage module establishes data communication connections with the status aggregation module, interlock management module, and permit scheduling module. It is used to receive personnel detection signals, emergency stop signals, and safety release receipts, and outputs operating mode switching results, speed limit strategies, restricted passage strategies, interlock incremental rules, permit restriction instructions, and gradual recovery instructions. This enables the AGV production line intelligent scheduling and optimization system to directly inject safety constraints into the passage permit link under real working conditions such as personnel entering the passage, forklifts temporarily passing through, and emergency stop button triggering. This avoids secondary congestion or secondary risks caused by vehicles rushing through at the moment of safety release.

[0079] The operating mode includes at least a normal mode and a restricted mode. In the normal mode, the interlock management module makes regular permission determinations according to the interlock condition set, and the permission scheduling module can issue access permits according to the task pool. In the restricted mode, the permission scheduling module is constrained by permission restriction instructions to reduce the scope of access permit issuance, and the interlock management module maintains a blocked state on the affected and controlled access resources.

[0080] Regarding the access of personnel detection signals and emergency stop signals, personnel detection signals can be output from safety light curtains on both sides of the passage, area laser scanners, video personnel recognition devices, or access control opening and closing sensors. Emergency stop signals can be output from on-site emergency stop buttons, vehicle emergency stop circuits, or safety relays. Regardless of the signal source, the safety linkage module uniformly converts them into safety event records with time stamps. The safety event record includes at least an event type marker, an event location marker, and a trigger resource identifier. The event type marker is used to distinguish between personnel detection signals and emergency stop signals, the event location marker is used to indicate the production line area corresponding to the event, and the trigger resource identifier is used to indicate the controlled access resource identifier affected by the event.

[0081] The safety release receipt is generated by the release signal corresponding to the personnel detection signal or emergency stop signal. For example, if no personnel are detected in the personnel detection area for a continuous period of time, the emergency stop button is reset and the safety circuit is restored to closure, the safety linkage module will convert the release signal into a safety release receipt and keep it consistent with the trigger resource identifier so that subsequent gradual recovery instructions can be aligned with the same range of influence.

[0082] Regarding the switching of operating modes and the issuance of policies, the safety linkage module generates a restricted mode flag when it detects the arrival of personnel detection signals or emergency stop signals. The restricted mode flag carries an event type flag, an event location flag, and a trigger resource identifier, and broadcasts the restricted mode flag to the interlock management module and the permission scheduling module. At the same time, the safety linkage module issues speed limit policies and traffic restriction policies to the affected vehicles.

[0083] The speed limit strategy is used to limit the maximum speed of a vehicle in the affected area. The speed limit strategy includes at least a set of vehicle identifiers, a speed limit area marker, and a target speed marker. The set of vehicle identifiers is obtained by filtering out the vehicle identifiers located within the speed limit area marker from the state frames output by the state aggregation module. The speed limit area marker is mapped from the event location marker. The restriction policy is used to restrict vehicles from entering affected controlled access resources or their entry point markers. The restriction policy includes at least a set of restricted resource identifiers and a restriction activation condition marker. The set of restricted resource identifiers consists of the trigger resource identifier and resource identifiers that form a mutually exclusive pair with the trigger resource identifier in the mutual exclusion table of the interlock management module, so as to avoid vehicles detouring into the mutually exclusive conflict zone and creating new risks.

[0084] After the speed limit policy and the traffic restriction policy are issued, the vehicle-side communication unit sends back an execution receipt, which is written into the event receipt for subsequent state consistency verification.

[0085] Regarding the injection of interlock incremental rules, the security linkage module generates interlock incremental rules based on the restricted mode marker and sends them to the interlock management module, so that the interlock management module sets the affected controlled access resources to a blocked state.

[0086] An interlock incremental rule includes at least a set of blocked resource identifiers, a block trigger condition flag, and a block release condition flag. The set of blocked resource identifiers must be consistent with or contain the set of prohibited resource identifiers. The block trigger condition flag corresponds to a personnel detection signal or an emergency stop signal, and the block release condition flag corresponds to a safety release receipt. After receiving the interlock incremental rule, the interlock management module writes the set of blocked resource identifiers into the block flag in the resource status table and puts the resource state machine corresponding to the set of blocked resource identifiers into a blocked state. Subsequently, it outputs a permission judgment result of "prohibited" and returns a blocking reason code for any passage permission application. This allows the permission scheduling module to generate a waiting instruction and prevent vehicles from entering the affected area. By injecting the blocking behavior in the form of an interlock incremental rule, the safety linkage module does not need to change the basic structure of the original interlock condition set of the interlock management module; it only applies incremental constraints to the specified resources during the duration of the restricted mode.

[0087] Regarding the issuance of permission restriction instructions, the security linkage module issues permission restriction instructions to the permission scheduling module to restrict the issuance of passage permits. Permission restriction instructions include at least a restriction scope marker and a restriction method marker. The restriction scope marker indicates the set of controlled access resources or vehicle identifiers targeted by the restriction, while the restriction method marker indicates whether the restriction is to suspend issuance, reduce concurrent issuance, or only allow issuance of tasks with specific priority markers. Upon receiving the permission restriction instruction, the permission scheduling module, during task pool advancement, suspends the initiation of passage permit applications for control segments involving restriction scope markers or only initiates passage permit applications for control segments not involving restriction scope markers, and keeps waiting instructions updated for vehicles already in a waiting state to prevent vehicles from congregating at the entrance of the blocked area under restricted mode.

[0088] For example, when an emergency stop signal is triggered and the event location marker is at an intersection or narrow passage entrance, a pause in issuance can be used as a restriction marking method; when a personnel detection signal is triggered and personnel are located in an edge passage, a reduction in concurrent issuance can be used as a restriction marking method to maintain the limited passage capacity of the production line.

[0089] Regarding the issuance of gradual recovery instructions, after receiving the security release receipt, the security linkage module generates a release confirmation mark and issues an interlock release rule to the interlock management module to release the blockade status. At the same time, it issues a phased recovery instruction to the permit scheduling module to resume the application for and issuance of permits.

[0090] The interlock release rule must include at least a set of release resource identifiers and a release effective condition flag. The set of release resource identifiers must be consistent with the set of block resource identifiers, and the release effective condition flag must correspond to a security release receipt. After receiving the interlock release rule, the interlock management module will transfer the resource state machine corresponding to the set of release resource identifiers from the block state to the pre-occupiable state and clear the block flag in the resource state table. The phased recovery instruction must include at least a recovery phase sequence and a phase switching condition flag. The recovery phase sequence is used to indicate the order in which controlled access resources are restored according to their priority. The priority of controlled access resources can be pre-configured by the resource configuration table or generated by sorting the conflict degree of the mutual exclusion table. The phase switching condition flag is used to indicate the state stability conditions that each phase needs to meet. The state stability conditions are determined by the event receipts continuously output by the state aggregation module. Specifically, the relevant controlled access resources have a complete pair of occupancy confirmation and idle confirmation in multiple consecutive control cycles and there are no permission timeout flags or circular wait flags.

[0091] During the phased recovery command execution, the safety linkage module maintains the speed limit policy without revoking, allowing vehicles to pass through the newly unblocked area at a low speed while maintaining a safe distance. Once the stability conditions are met, the safety linkage module removes the speed limit policy and cancels the permission restriction command, completing the switch from the restricted mode marker to the normal mode marker, thereby achieving a gradual transition from safety de-blocking to production line recovery.

[0092] For example, in a real-life scenario: when personnel enter the narrow passage of the production line to pick up or put down materials, the safety light curtain outputs a personnel detection signal and carries a trigger resource identifier as the narrow passage resource identifier. The safety linkage module immediately generates a restricted mode mark and issues a speed limit policy, causing vehicles approaching the narrow passage entrance to slow down. At the same time, a no-entry policy is issued to prohibit other vehicles from entering the narrow passage. The safety linkage module injects interlock incremental rules into the interlock management module, causing the narrow channel resource identifier to enter a blocked state. The interlock management module returns a permission prohibition to subsequent passage permission applications and provides a blocking reason code. Based on this, the permission scheduling module issues waiting instructions to relevant vehicles and suspends the issuance of passage permission orders for this control segment. After the personnel leave, the safety light curtain outputs a release signal to form a safety release receipt. The safety linkage module first issues an interlock release rule to release the blockade, and then issues a phased recovery instruction. Priority is given to restoring the passage on the narrow passage exit side to evacuate the queued vehicles, and then the passage on the entrance side is restored. During the recovery phase, the speed limit policy will remain in effect until the lane status is stable after roadside occupancy and vacancy confirmations are received. Then, the permission restriction order and speed limit policy will be revoked, and the system will return to normal mode.

[0093] Through the aforementioned methods of switching operating modes, issuing strategies, interlocking incremental injection, and implementing permission restrictions and gradual recovery, the safety linkage module can integrate safety constraints and access permissions in a closed loop within the AGV production line intelligent scheduling and optimization system.

[0094] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.

[0095] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0096] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.

[0097] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0098] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. An intelligent scheduling and optimization system for AGV production lines, characterized by: It includes a status aggregation module, an interlock management module, a permission scheduling module, a rollback and recovery module, and a security linkage module, and the modules are connected through data communication. The status aggregation module is used to receive task requests, vehicle status, roadside occupancy confirmations and vacancy confirmations, and generate status frames and event receipts. The interlock management module is used to determine the controlled access resources based on the status frame and establish a mutual exclusion table, generate an interlock condition set and resource state machine, register the pre-occupancy status of the target resource sequence carried by the access permit application, and trigger the transition from the pre-occupancy status to the occupancy status with the entry receipt and occupancy confirmation, and trigger the transition from the occupancy status to the idle status with the exit receipt and idle confirmation. The permit scheduling module is used to generate a task pool and divide the control segment according to the controlled access resource boundary. Before the vehicle enters the control segment, it initiates a pass permit application to the interlock management module, records the permit waiting time and outputs the permit timeout flag, and issues a pass permit order or waiting instruction according to the permit result. The rollback recovery module is used to construct waiting dependencies based on waiting instructions, pre-occupancy status and resource state mechanism, identify cyclic waiting flags or permission timeout flags, freeze the passage permission issuance instructions and issue rollback sequences to selected vehicles. The rollback sequence includes a retreat path, retreat point confirmation, resource release and control segment reconnection. The safety linkage module is used to trigger the switching of operating modes and issue speed limit and prohibition policies based on personnel detection signals or emergency stop signals, inject interlock incremental rules into the interlock management module and issue permission restriction instructions to the permission scheduling module, and issue progressive recovery instructions based on safety release receipts. The rollback recovery module sends a rollback sequence to the selected vehicle. The rollback sequence includes the rollback path, rollback point confirmation, resource release, and control segment reconnection, including: Issue a speed limit action to the selected vehicle and initiate a yielding permission application, which includes the yielding path and yielding point markings. After the interlock management module outputs an access mark for the yield permission application, it issues a yield execution command to drive the vehicle along the yield path to the yield point, and collects the yield point confirmation and writes it into the event receipt. When the event receipt detects that the yield point has been reached, the pre-occupancy record corresponding to the selected vehicle is cancelled and the occupancy status is transferred to the idle status, generating a resource release receipt. After the resource release receipt arrives, a control segment reattachment instruction is output to the permit scheduling module to bind the selected vehicle back to the control segment to be entered in the original control segment sequence, and the frozen passage permit issuance instruction is released.

2. The AGV production line intelligent scheduling and optimization system according to claim 1, characterized in that: The status aggregation module receives task requests, vehicle status, roadside occupancy confirmations, and idle confirmations, generating status frames and event receipts, including: Extract the task identifier, start identifier, end identifier, and priority flag from the task request, and associate them with the vehicle identifier; Extract pose markers, cargo markers, mission phase markers, and fault markers from the vehicle status and form vehicle status subframes; Extract resource identifiers and confirmation type markers from roadside occupancy and vacancy confirmations, and form roadside status subframes; Perform unified time reference alignment on vehicle state subframes and roadside state subframes, and encapsulate the alignment result into a state frame; The vehicle entry receipt, vehicle exit receipt, roadside occupancy confirmation, and roadside vacancy confirmation are paired according to vehicle identifier and resource identifier, and event receipts are generated and output to the interlock management module and the permit scheduling module.

3. The AGV production line intelligent scheduling and optimization system according to claim 2, characterized in that: The interlock management module determines the controlled access resources based on the state frame and establishes a mutual exclusion table, generating an interlock condition set and a resource state machine, including: The controlled access resource set is determined based on the resource identifier in the roadside status subframe, and an entry point marker and an exit point marker are configured for each controlled access resource. A mutex table is generated based on the set of controlled access resources. The mutex table records resource mutual exclusion pairs and mutual exclusion direction markers. An interlocking condition set is generated based on a mutex table and a state frame. The interlocking condition set includes at least a mutual exclusion occupancy condition, a closed prohibition condition, and a buffer capacity condition. A resource state machine is established based on the interlock condition set. The resource state machine includes idle state, pre-occupied state and occupied state, and a resource state table is generated to output the permission determination result to the permission scheduling module.

4. The AGV production line intelligent scheduling and optimization system according to claim 3, characterized in that: The permit scheduling module generates a task pool and divides the control segment according to the controlled access resource boundary. Before a vehicle enters the control segment, it initiates a access permit application to the interlock management module, records the permit waiting time, and outputs a permit timeout flag, including: The tasks in the task pool are parsed into a sequence of control segments arranged in execution order, and each control segment is bound to a target resource sequence and a candidate yield point marker. A passage permit application is generated for the control segment to be entered. The passage permit application carries the vehicle identification, target resource sequence and entry order mark; After a permit application is initiated, a permit waiting timer is started, and when the permit waiting timer reaches a preset time limit, a permit timeout flag is generated and output to the rollback and recovery module. Receive the permission determination result output by the interlock management module, issue a passage permission order when permission is granted, and issue a waiting instruction with a blocking reason code when permission is denied.

5. The AGV production line intelligent scheduling and optimization system according to claim 4, characterized in that: The interlock management module registers the pre-occupancy status of the target resource sequence carried in the access permit application, and drives the resource state machine to complete the state transition based on the event receipt, including: Write a pre-occupancy record for each controlled access resource in the target resource sequence, and associate the pre-occupancy record with the vehicle identifier and the entry sequence marker; When both the entry receipt and the occupancy confirmation are satisfied in the event receipt, the corresponding controlled access resource will be transferred from the pre-occupancy state to the occupancy state, and other pre-occupancy records of the same controlled access resource will be cleared. When both the exit receipt and the idle confirmation are satisfied in the event receipt, the corresponding controlled access resource will be transferred from the occupied state to the idle state. When the permit timeout flag corresponding to the permit waiting timer arrives, the pre-occupancy record in the target resource sequence is revoked and the corresponding controlled access resource is restored to an idle state. The interlock management module outputs permission determination results based on the interlock condition set, resource status table, and pre-occupancy record. The permission determination results include access flags and blocking reason codes.

6. The AGV production line intelligent scheduling and optimization system according to claim 5, characterized in that: The rollback and recovery module constructs waiting dependencies based on waiting instructions, pre-emptive states, and resource state machines, and identifies circular wait flags, including: The waiting resource identifier is determined based on the blocking reason code carried by the waiting instruction, and a waiting edge is established between the vehicle identifier and the waiting resource identifier; The occupying vehicle identifier is determined based on the pre-occupancy record and occupancy status in the resource status table, and the waiting edge is connected to the occupying vehicle identifier to form a dependency edge; When a closed loop is formed by the dependent edges, a circular wait flag is generated, and a freeze permit issuance instruction is output to the permit scheduling module. The set of candidate vehicles for backoff is determined based on the cyclic waiting flag. The set of candidate vehicles for backoff includes vehicle identifiers that occupy bottleneck-controlled passage resources and have a backoff point flag. The loop wait flag and the set of candidate vehicles for rollback are output for rollback sequence generation.

7. The AGV production line intelligent scheduling and optimization system according to claim 6, characterized in that: The rollback recovery module triggers rollback sequence generation and performs resource release when the permission timeout flag is reached, including: Receive the license timeout flag output by the license scheduling module, and determine the corresponding vehicle identifier and target resource sequence based on the license timeout flag; Add the corresponding vehicle identifier to the rollback candidate vehicle set, and mark the pre-occupancy record in the target resource sequence as timed-out pre-occupancy; Output a freeze permit issuance instruction to the permit scheduling module and determine the selected vehicle based on the timeout pre-occupancy; Generate a reversal sequence for the selected vehicle and issue a reversal execution command to enable the selected vehicle to drive along the reversal path into the reversal point to complete the reversal point confirmation; After confirming arrival at the yield point, the timeout pre-occupancy is revoked and a resource release receipt is generated. A control segment reattachment instruction is then sent to the permit scheduling module to resume the permit application process.

8. The AGV production line intelligent scheduling and optimization system according to claim 7, characterized in that: The safety linkage module triggers an operating mode switch based on personnel detection signals or emergency stop signals and injects incremental interlock rules into the interlock management module, including: When a personnel detection signal or emergency stop signal arrives, a restricted mode flag is generated, and a permission restriction instruction is output to the permission scheduling module to restrict the issuance of passage permits; The set of affected controlled access resources is determined based on the restricted mode marker, and interlock incremental rules are issued to the interlock management module to put the affected controlled access resources into a blocked state. Speed ​​limit and traffic restriction policies are issued to affected vehicles, and execution receipts are collected and written into event receipts; The interlock management module outputs the blocking reason code for the access permit application based on the blocking status and maintains the interlock condition set update result.

9. The AGV production line intelligent scheduling and optimization system according to claim 8, characterized in that: The security linkage module issues a progressive recovery command based on the security deactivation receipt to restore the application for and issuance of travel permits, including: Receive the security release receipt and generate a release confirmation flag, and issue the interlock release rule to the interlock management module to transfer the affected controlled access resources from the blocked state to the pre-occupied state; Output phased recovery instructions to the permit scheduling module so that the access permits are restored and issued in sequence according to the priority of the controlled access resources, and collect occupancy confirmation and idle confirmation to update the resource status table in each phase; During the phased recovery command execution, the speed limit policy is maintained until the resource release receipt of the affected controlled traffic resources reaches the preset stability condition. Once the stability conditions are met, the speed limit policy is lifted and the license restriction instruction is revoked, completing the switch from the restricted mode flag to the normal mode flag.

Citation Information

Patent Citations

  • Multi-AGV (Automatic Guided Vehicle) cooperative scheduling method and system and related equipment

    CN116132943A

  • Automatic guided vehicle path planning method and device and computer readable storage medium

    CN119469180A