Operation control system, method, device and product of autonomous vehicle

Through the collaborative work of cloud-based decision-making and vehicle-side execution modules, autonomous vehicles have achieved automated shutdown control in ultra-ODD scenarios, improving operational efficiency and safety, and solving the inefficiency problem of manual shutdown.

CN122069294APending Publication Date: 2026-05-19APOLLO INTELLIGENT DRIVING (BEIJING) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
APOLLO INTELLIGENT DRIVING (BEIJING) TECHNOLOGY CO LTD
Filing Date
2026-02-13
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing autonomous vehicles require manual shutdown in extreme weather conditions beyond the ODD range, lacking an automated shutdown control system, resulting in low operational efficiency and insufficient safety.

Method used

An operation control system for autonomous vehicles is provided, including a cloud-based operation decision center, a vehicle-side control execution module, and a remote driving control subsystem. It can automatically send a stop command when a super ODD scenario is detected and perform a parking operation on the vehicle or in the cloud to ensure safe parking of the vehicle.

Benefits of technology

It enables automated shutdown control under severe weather conditions, improves operational control efficiency and safety, and ensures that vehicles can safely and autonomously or remotely dock in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122069294A_ABST
    Figure CN122069294A_ABST
Patent Text Reader

Abstract

The invention provides an operation control system, method and device of an automatic driving vehicle, electronic equipment, a storage medium and a computer program product, relates to the technical field of computers, in particular to the technical fields of automatic driving, cloud computing and the like, and can be applied to an operation control scene of the automatic driving vehicle. According to the specific implementation scheme, a cloud operation decision center is used for responding to the situation that the automatic driving vehicle runs in an overrun scene and sending a stop instruction to a vehicle end control execution module of the automatic driving vehicle; the vehicle end control execution module is used for responding to the stopping instruction and controlling the automatic driving vehicle to execute vehicle end stopping operation; and the remote driving control subsystem is used for controlling the automatic driving vehicle to execute the cloud parking operation in response to the failure of the execution of the vehicle end parking operation by the automatic driving vehicle. The invention provides an automatic operation control system, and the operation control efficiency and the operation safety in an overrun scene are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, specifically to the fields of autonomous driving and cloud computing, and in particular to an operation control system, method, device, electronic equipment, storage medium, and computer program product for autonomous vehicles, which can be applied to the operation control scenarios of autonomous vehicles. Background Technology

[0002] When severe weather exceeding the ODD (Operational Design Domain) occurs, such as hail, heavy rain, or typhoons, it is necessary to shut down autonomous vehicles in operation. Currently, the entire shutdown process requires manual intervention. Summary of the Invention

[0003] This disclosure provides an operation control method, apparatus, electronic device, storage medium, and computer program product for an autonomous vehicle.

[0004] According to the first aspect, an operation control system for an autonomous vehicle is provided, comprising: a cloud-based operation decision center, used to send a stop command to the vehicle-side control execution module of the autonomous vehicle in response to detecting that the autonomous vehicle is operating in an over-limit scenario; a vehicle-side control execution module, used to control the autonomous vehicle to perform a vehicle-side docking operation in response to the stop command; and a remote driving control subsystem, used to control the autonomous vehicle to perform a cloud-based docking operation in response to the failure of the vehicle-side docking operation.

[0005] According to the second aspect, an operation control method for an autonomous vehicle is provided, comprising: responding to a stop command for the autonomous vehicle and determining the current road scenario in which the autonomous vehicle is located; and adopting a parking strategy corresponding to the road scenario to control the autonomous vehicle to perform vehicle-side parking operations.

[0006] According to a third aspect, an operation control device for an autonomous vehicle is provided, comprising: a scenario determination unit configured to determine the current road scenario of the autonomous vehicle in response to a stop command for the autonomous vehicle; and a parking unit configured to control the autonomous vehicle to perform vehicle-side parking operations by adopting a parking strategy corresponding to the road scenario.

[0007] According to a fourth aspect, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a method as described in any implementation of the second aspect.

[0008] According to a fifth aspect, a non-transitory computer-readable storage medium is provided that stores computer instructions for causing a computer to perform the method described in any implementation of the second aspect.

[0009] According to a sixth aspect, a computer program product is provided, comprising: a computer program that, when executed by a processor, implements the method as described in any implementation of the second aspect.

[0010] According to the technology disclosed herein, an operation control system for autonomous vehicles is provided. A cloud-based operation decision center is used to send a stop command to the vehicle-side control execution module of the autonomous vehicle in response to the detection that the autonomous vehicle is operating in an over-limit scenario. The vehicle-side control execution module is used to respond to the stop command and control the autonomous vehicle to perform a vehicle-side docking operation. A remote driving control subsystem is used to respond to the failure of the autonomous vehicle to perform a vehicle-side docking operation and control the autonomous vehicle to perform a cloud-based docking operation. This provides an automated operation control system that improves the operation control efficiency and operation safety in over-limit scenarios.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0012] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 This is an exemplary system architecture diagram that can be applied to an embodiment of this disclosure; Figure 2 This is a schematic diagram of the structure of the operation control system for an autonomous vehicle according to this disclosure; Figure 3 This is a timeline diagram of the operation control system during shutdown according to this embodiment; Figure 4 This is a timeline diagram of the operation recovery process according to this embodiment; Figure 5 This is a schematic diagram of the exception handling mechanism according to this embodiment; Figure 6 This is a flowchart of an operation control method for an autonomous vehicle according to this embodiment; Figure 7 This is a schematic diagram illustrating an application scenario of the operation control method for autonomous vehicles according to this embodiment; Figure 8 This is a structural diagram of one embodiment of the operation control device for an autonomous vehicle according to the present disclosure; Figure 9This is a schematic diagram of the structure of a computer system suitable for implementing the embodiments of the present disclosure. Detailed Implementation

[0013] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0014] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0015] Figure 1 An exemplary architecture 100 is shown for an operation control system, method, and apparatus for autonomous vehicles to which the present disclosure can be applied.

[0016] like Figure 1 As shown, the system architecture 100 may include vehicle-mounted devices 101, 102, and 103, a network 104, and a server 105. The communication connections between vehicle-mounted devices 101, 102, and 103 form a topology network, and network 104 serves as the medium for providing communication links between vehicle-mounted devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0017] Vehicle-side devices 101, 102, and 103 can be hardware or software that supports network connectivity for data interaction and processing. When vehicle-side devices 101, 102, and 103 are hardware, they can be various electronic devices that support network connectivity, information acquisition, interaction, display, and processing functions, including but not limited to onboard computers, sensors, etc. When vehicle-side devices 101, 102, and 103 are software, they can be installed in the aforementioned electronic devices. They can be implemented as, for example, multiple software programs or software modules to provide distributed services, or as a single software program or software module. No specific limitations are imposed here.

[0018] Server 105 can be a server that provides various services, such as acquiring environmental data uploaded by vehicle-side devices 101, 102, and 103, and controlling the autonomous vehicle to stop operation in response to detecting that the autonomous vehicle is operating in an excessive-limit scenario. As an example, server 105 can be a cloud server.

[0019] It should be noted that a server can be either hardware or software. When the server is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When the server is software, it can be implemented as multiple software programs or software modules (such as software programs or software modules used to provide distributed services), or as a single software program or software module. No specific limitations are made here.

[0020] It should also be noted that the operation control method for autonomous vehicles provided in the embodiments of this disclosure is generally executed by the vehicle-side equipment, but the possibility of it being executed by the server, or by the server and the vehicle-side equipment cooperating with each other, is not excluded. Accordingly, the various parts (e.g., various units) included in the operation control device for autonomous vehicles can be all set in the vehicle-side equipment, all set in the server, or set in the server and the vehicle-side equipment respectively.

[0021] It should be understood that Figure 1 The number of vehicle-mounted devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of vehicle-mounted devices, networks, and servers can be included. When the electronic equipment on which the autonomous vehicle's operation control method runs does not require data transmission with other electronic equipment, the system architecture may only include the electronic equipment (e.g., vehicle-mounted devices or servers) on which the autonomous vehicle's operation control method runs.

[0022] Please refer to Figure 2 , Figure 2 This is a schematic diagram of the structure of an operation control system for an autonomous vehicle provided in an embodiment of this disclosure. (Continue referring to...) Figure 3 This illustrates the timing diagram of the operation control system during a shutdown process. The operation control system 200 includes the following components: The cloud-based operation decision center 201 is used to send a stop command to the vehicle-side control execution module of the autonomous vehicle in response to the detection that the autonomous vehicle is operating in an excessive scenario. The vehicle-side control execution module 202 is used to respond to the stop command and control the autonomous vehicle to perform a vehicle-side docking operation. The remote driving control subsystem 203 is used to respond to the failure of the autonomous vehicle to perform a vehicle-side docking operation and control the autonomous vehicle to perform a cloud-based docking operation.

[0023] Exceeding limits, also known as exceeding the Design Operating Domain (ODD) or extreme scenarios, specifically refers to a set of scenarios where the operating environment or the vehicle's own state has exceeded the preset safety boundaries of its "design operating domain," and continued operation would significantly increase safety risks or violate operating rules. The core of determining the scenario set lies in the mismatch between objective conditions and preset safety capabilities, and its triggering is based on a series of monitorable objective parameter thresholds.

[0024] For example, when the system detects extreme weather conditions in the area where the vehicle is located (such as dense fog, heavy rain, or blizzards with visibility below design values), or encounters serious road anomalies (such as sudden traffic control or road closures due to major accidents), or when the vehicle's critical systems experience performance degradation or malfunctions, it can be determined that the system has entered an over-limit scenario. At this point, the system's core objective shifts from "providing service" to "ensuring safety," thereby triggering the subsequent automated shutdown process.

[0025] The cloud-based operations decision center, deployed in the cloud, is the command core of the operations control system. It continuously monitors the overall operational status of autonomous vehicles and external environmental information, and is responsible for making the highest-level policy judgments. When it determines, based on preset rules (such as weather warnings, traffic control instructions, or system performance thresholds), that a particular vehicle or a batch of vehicles is under abnormal conditions that prevent it from operating safely and continuously (operating in an over-limit scenario), it generates and issues a clear shutdown control to stop the autonomous vehicles from operating. This is the decision-making starting point that triggers the entire automated shutdown process.

[0026] The vehicle-side control execution module is the core control entity deployed locally in an autonomous vehicle. It is the core executor of system commands, such as the vehicle-side PNC (Planning and Control module). The vehicle-side control execution module interacts directly with the autonomous vehicle's sensors, planner, and drive-by-wire chassis, possessing the ability to perceive the vehicle's surrounding environment in real time, plan driving paths, and directly control vehicle movement. Upon receiving a stop command, this module autonomously assumes the primary responsibility of controlling the vehicle to a safe stop. Its execution process does not require continuous reliance on remote commands, demonstrating a high degree of autonomy and real-time performance.

[0027] The remote driving control subsystem is a collection of professional remote driving support capabilities provided in the cloud, serving as an effective supplement and strong backup to the vehicle's autonomous control capabilities. It does not participate in regular driving, but is authorized to intervene when the vehicle's control execution module fails to complete a parking task due to environmental complexity or system limitations, ensuring that a method can be found to bring the vehicle to a safe state under any circumstances.

[0028] As an example, after the system starts, the cloud-based operation decision center continuously analyzes global data. When it determines, through the connected weather warning system and the real-time perception data transmitted by the vehicle, that the autonomous vehicle is entering a foggy area with rapidly decreasing visibility (i.e., an over-limit scenario), it immediately generates a stop command and sends it to the autonomous vehicle. The vehicle-side control execution module responds to the command within milliseconds, and then, based on its own sensor data, quickly plans a safe stopping path on the side of the road ahead, smoothly controls the vehicle to decelerate, change lanes, and finally stop at the predetermined position, completing a complete "vehicle-side stopping operation" that is autonomously decided and executed by the vehicle.

[0029] As another example, the cloud-based operations decision center, based on information from the traffic management platform, detects that a section of road ahead of an autonomous vehicle is about to be closed due to a sudden accident and immediately issues a stop command. Upon receiving the command, the vehicle-side control execution module attempts to pull over, but due to the right side of the road being full of parked vehicles, it cannot find sufficient parking space, resulting in a failed "vehicle-side parking operation." This failure is reported in real time. At this point, the remote driving control subsystem is activated and intervenes. Based on a more comprehensive cloud map and real-time information, it plans a new route for the autonomous vehicle to detour to an empty parking area behind it and sends this "cloud-based parking route" command to the vehicle-side control execution module via a secure link, ultimately controlling the vehicle to successfully park. This process constitutes a "cloud-based parking operation."

[0030] To ensure the reliability of the shutdown order, it can be triggered proactively or after confirmation by the cloud-based operations decision-making center under specific conditions. Specifically, when the cloud-based operations decision-making center initially identifies potential risks that may constitute over-limit scenarios through various data channels (such as weather warning systems, traffic incident platforms, or vehicle abnormality reports), the process is not fully automated. Instead, a manual confirmation and decision enhancement step is introduced to ensure the prudence and reliability of the operational decision.

[0031] First, relevant early warning information and a list of potentially affected vehicles are pushed to the internal collaboration and information synchronization platform used by operations and maintenance personnel. Operations and maintenance personnel in different roles (such as cloud cabin monitors and command center dispatchers) use this platform to perform necessary information synchronization, risk assessment, and operational confirmation communication. This step ensures the integration of human expert experience with system early warnings and completes the final review and reporting of the scope (batch or single vehicle) of vehicles to be subject to shutdown operations.

[0032] Subsequently, authorized personnel execute the final instruction issuance operation on the management interface provided by the cloud-based operations decision center. This operation is essentially a final confirmation and authorization of the shutdown decision prepared by the system. Personnel can choose different control granularities such as "batch shutdown" or "single vehicle shutdown". Once confirmed, the cloud-based operations decision center officially generates an executable shutdown instruction and accurately issues it to the vehicle-side control execution module of the target vehicle.

[0033] In some optional implementations of this embodiment, the vehicle-side control execution module 201 is further configured to: respond to a stop command, determine the current road scenario of the autonomous vehicle, and control the autonomous vehicle to perform a vehicle-side stop operation by adopting a stop strategy corresponding to the road scenario.

[0034] A road scenario refers to the type of environment in which an autonomous vehicle operates when performing a parking maneuver, defined by the road's physical structure, traffic rules, and real-time traffic flow. Its core characteristics directly determine the available legal and safe parking behavior modes. By fusing and analyzing vehicle location, road attribute data (such as lane line type, barriers, and traffic signs), and real-time perception information, the current scenario category is determined, serving as input for subsequent decisions.

[0035] The classification of "road scenarios" can be flexibly defined and identified using different rule systems and classification granularities based on actual technical and operational needs. For example: 1. When classifying road scenarios according to the rules of road physical and functional attributes, the coarse-grained road scenario types include closed roads (such as highways and fully enclosed expressways) and open roads (such as ordinary urban roads with at-grade intersections). In open roads, the fine-grained road scenario types can be further divided into arterial roads, secondary arterial roads, and branch roads; or in closed roads, they can be divided into highway main lines, ramps, and hub interchange areas.

[0036] 2. When classifying road scenarios according to traffic flow characteristics, the coarse-grained road scenario types include continuous flow scenarios (vehicles maintain a stable and continuous flow) and intermittent flow scenarios (vehicles frequently start and stop due to interference from intersection signals and pedestrians). In continuous flow scenarios, the fine-grained road scenario types can be further subdivided into unobstructed flow and synchronous flow (vehicles follow stably); in intermittent flow scenarios, they can be further subdivided into signal-controlled intersections, unsignal-controlled intersections, or pedestrian crossing areas.

[0037] 3. When classifying road scenarios according to laws and operational management rules, the coarse-grained road scenario types include roads that allow temporary parking and roads that prohibit parking. Within roads that allow parking, the specific types of areas where parking is permitted can be further specified, such as roadside parking lanes, bus stop areas (outside of operating hours), and designated temporary passenger pick-up and drop-off areas.

[0038] A parking strategy refers to a set of predefined control logic and path planning rules tailored to a specific road scenario, guiding autonomous vehicles to safely transition from a driving state to a stationary parking state. Each strategy clarifies the core objective of the parking process (e.g., parking within the lane or moving to a specific area on the roadside), the path generation method (e.g., whether it is necessary to deviate from the currently planned path), and the priority control method (e.g., immediate braking or finding a suitable location). The selection of a parking strategy aims to ensure that parking behavior complies with traffic regulations while maximizing the adaptation to safety constraints and efficiency requirements under specific scenarios.

[0039] As an example, upon receiving a stop command, the vehicle-side control execution module first uses onboard sensors (such as cameras and LiDAR) to perceive the environmental characteristics around the vehicle in real time, while simultaneously acquiring the static attributes of the road using high-precision map data. The module then fuses and analyzes this information, matching the "road scenario" category that best suits the current overall conditions in real time. Subsequently, the module retrieves the "parking strategy" bound to this category from a pre-set strategy library. For example, if the analysis indicates that the current environment allows parking and there is a clearly defined non-traffic area for parking, a strategy centered on "finding and moving to a safe parking space" is adopted; if the analysis indicates that the vehicle must remain within the driving lane, a strategy centered on "decelerating to a stop within the current lane" is adopted. Finally, based on the rules of the selected strategy, the module generates specific control commands in real time to complete the parking process.

[0040] As another example, after responding to a stop command, the vehicle-mounted control execution module first obtains the vehicle's precise location coordinates via the Global Positioning System (GPS). These coordinates are then sent to the cloud or matched against a pre-installed high-precision map database on the vehicle to quickly obtain the legal attributes and design characteristics of the road segment where the vehicle is located (such as road grade, whether it is fully enclosed, minimum speed limit, etc.). Based on this objective, pre-defined road attribute data, the vehicle-mounted control execution module directly determines the corresponding standardized "road scenario." Next, according to an internally pre-defined "scenario-policy" mapping table, the vehicle-mounted control execution module automatically selects and loads the corresponding standardized "stopping strategy." This strategy includes an optimized standard stopping procedure for roads with these attributes. Finally, the vehicle-mounted control execution module, considering the vehicle's current state (such as speed and heading), executes this standard procedure to control the autonomous vehicle to complete the stop.

[0041] In this implementation, by first identifying the road scenario and then matching the corresponding strategy, the scenario adaptation of parking control is achieved. This significantly improves the safety, compliance and success rate of automatic parking in complex road networks, and avoids the limitations of a single strategy.

[0042] In some optional implementations of this embodiment, the road scenario includes an open road scenario. An open road scenario refers to a driving environment with the following core characteristics: the road itself is not fully enclosed or physically isolated, allowing vehicles to turn and merge at multiple intersections; the traffic participants are diverse and there is mixed traffic flow, potentially including motor vehicles, non-motor vehicles, and pedestrians; simultaneously, roadside areas or specific permitted parking spaces (such as parking lanes or temporary parking spots) are typically provided along the road. In this type of scenario, vehicle parking behavior has a certain degree of flexibility and spatial selectivity, but it also faces more complex dynamic obstacle interference.

[0043] Typical open road scenarios include, but are not limited to, main roads, secondary roads, and branch roads within urban areas, as well as non-enclosed highways in towns and villages. For example, a city street with traffic lights, pedestrian crossings, and commercial entrances or designated parking spaces on both sides is an example of an open road scenario. The core task of stopping on such roads is, while adhering to traffic rules, to find and safely arrive at an appropriate stopping position within the dynamic, shared right-of-way space.

[0044] In this implementation, the vehicle-side control execution module 201 is further used to: in response to the autonomous vehicle being in an open road scenario, determine the parking position based on the current environment of the autonomous vehicle; generate a vehicle-side parking route from the current position of the autonomous vehicle to the parking position; and control the autonomous vehicle to perform a vehicle-side parking operation based on the vehicle-side parking route.

[0045] Upon determining that the autonomous vehicle is in an open road scenario and receiving a stop command, the vehicle-side control execution module immediately initiates a system-wide stopping procedure. First, it integrates real-time perception data (such as LiDAR and camera detection of surrounding vehicles, pedestrians, and curbs) with high-precision map information. Based on preset safety and compliance rules (such as avoiding intersections, fire hydrants, and bus stops), it calculates and selects an optimal stopping location within the reachable area in front of the vehicle. This location is typically situated in a legal and spacious roadside area.

[0046] Once the target location is selected, the vehicle-side control execution module immediately performs path planning. Starting from the vehicle's current pose and ending at the target parking position, it takes into account real-time obstacle prediction and traffic rule constraints to generate a smooth, safe, and efficient vehicle-side parking route. This route includes the entire trajectory from changing from the current lane to the target parking lane and finally smoothly entering the parking position.

[0047] Finally, the vehicle-side control execution module decomposes the planned vehicle-side parking route into a series of specific longitudinal (acceleration / braking) and lateral (steering) control commands, which are precisely executed by the vehicle drive-by-wire system to control the vehicle to automatically travel along the route until it accurately and smoothly stops at the predetermined parking position, thus completing the entire vehicle-side parking operation.

[0048] In this implementation, a dedicated process is designed for the characteristics of open road scenarios, enabling autonomous vehicles to actively find compliant parking spots and plan safe routes. This significantly improves the success rate, compliance, and safety of automatic parking in complex urban traffic environments, and avoids traffic interference caused by blind parking.

[0049] In some optional implementations of this embodiment, in open road scenarios, the vehicle-side parking operation is completed by combining the vehicle-side control and operation module and the vehicle-side intelligent agent in the system.

[0050] The vehicle-side intelligent agent is the core decision-making, coordination, and state management entity deployed on the vehicle side of the operation and control system for autonomous vehicles. As the coordination hub for vehicle-side functional modules and the vehicle-side execution agent for cloud commands, it is primarily responsible for integrating information at the local vehicle level, driving business processes, maintaining operational status, and managing communication with the cloud. The vehicle-side intelligent agent in this disclosure has the following functions: 1. Business Process and State Management: The vehicle-side intelligent system embeds and maintains the complete set of operational business process logic and corresponding operational state machines (such as idle, in operation, out of service, out of service, and resumed operation). It is responsible for receiving and parsing macro-level instructions (such as stop instructions and resume instructions) issued from the cloud, and driving the state machine to perform precise transitions accordingly, thereby triggering or coordinating other modules on the vehicle side to execute corresponding specific tasks.

[0051] 2. Vehicle-side module coordination and control: At each stage of the state machine transition, the vehicle-side intelligent agent sends specific control requests or parameters to vehicle-side sub-modules such as the vehicle-side control execution module according to preset logic. For example, during a shutdown, it may initiate a route planning request containing a specific target (such as a stop point) to the control execution module and instruct it to execute it.

[0052] 3. Vehicle-to-Cloud Communication and Information Hub: The vehicle-side intelligent agent is the core interface for business communication between autonomous vehicles and the cloud-based operation and decision-making center and remote driving control subsystem. It is responsible for reporting vehicle status, task execution results (success or failure), and important events perceived locally (such as abnormal hand-raising) to the cloud in real time and in a structured manner. At the same time, it is also responsible for receiving and parsing various control commands and policy information issued by the cloud to ensure vehicle-to-cloud status synchronization and command closed loop.

[0053] Specifically, the vehicle-side control execution module is further used to determine the parking position based on the current environment of the autonomous vehicle in an open road scenario; the vehicle-side intelligent agent is used to generate the vehicle-side parking route from the current position of the autonomous vehicle to the parking position; and the vehicle-side control execution module is further used to control the autonomous vehicle to perform the vehicle-side parking operation based on the vehicle-side parking route.

[0054] As an example, after determining that the vehicle is in an open road scenario and receiving a stop instruction, the vehicle-side control execution module immediately initiates the environmental perception and decision-making process. It integrates real-time sensor data and map information, and calculates and determines an optimal stopping position in the roadside area in front of the vehicle based on safe distances, regulatory constraints (such as no-parking signs), and real-time obstacle positions.

[0055] Once the location is determined, the vehicle-side control execution module sends this parking location information to the vehicle-side intelligent agent. The vehicle-side intelligent agent, acting as the vehicle-side task scheduler and planning coordinator, then independently executes a path planning algorithm based on the vehicle's real-time reported current location and the received parking location. It comprehensively considers road topology, traffic rules, and predicted dynamic traffic flow to generate a safe and efficient vehicle-side parking route from the current location to the parking location.

[0056] After generating the route, the vehicle-side intelligent agent sends the complete vehicle-side parking route back to the vehicle-side control execution module and issues an execution command. The vehicle-side control execution module then uses its underlying vehicle control unit to perform precise closed-loop control of the steering wheel, accelerator, and brakes according to the route, driving the vehicle automatically and smoothly along the predetermined route, and finally accurately parking at the target parking position, completing the entire operation.

[0057] In this implementation, by placing the "location decision" and "route planning" functions in two collaborative modules on the vehicle side, a clear decoupling of the task level is achieved, which improves the modularity of the system and the reliability of decision-making, and facilitates independent optimization of functions and system maintenance.

[0058] In some optional implementations of this embodiment, the entire parking process in the vehicle-side intelligent agent maintenance and operation control system is carried out in an open road scenario. Specifically, the vehicle-side intelligent agent is also used to send a cloud-based parking request to the remote driving control subsystem in response to the failure of the autonomous vehicle to perform a vehicle-side parking operation.

[0059] In this implementation, the remote driving control subsystem is further used to: respond to cloud docking requests and generate cloud docking routes; and control the autonomous vehicle to perform cloud docking operations according to the cloud docking routes.

[0060] As an example, in an open road scenario, when the vehicle-side control execution module attempts to complete the vehicle-side parking operation based on the parking route generated by itself or the vehicle-side intelligent agent, but the operation fails due to sudden environmental changes (such as the sudden appearance of an immovable obstacle on the predetermined route) or control deviation exceeding the threshold, the vehicle-side intelligent agent will detect this failure state in real time.

[0061] Subsequently, the vehicle-side intelligent agent immediately encapsulates the vehicle's current precise location, attitude, surrounding environment perception summary, and parking failure reason to form a structured cloud parking request. This request is used to ask the cloud-based remote driving control subsystem to generate a parking path (cloud parking route) and is sent to the remote driving control subsystem through the vehicle-cloud communication link.

[0062] Upon receiving the cloud-based parking request, the remote driving control subsystem, based on its access to more global and real-time cloud data (such as a regional panoramic map and real-time traffic event information), and combined with the vehicle status in the cloud-based parking request, recalculates the route and generates a completely new cloud-based parking route from the vehicle's current location to the original or new parking location, avoiding the difficulties encountered by the vehicle.

[0063] Finally, the remote driving control subsystem sends the generated cloud-based parking route as a control command via a secure link to the vehicle-side control execution module of the autonomous vehicle. The vehicle-side control execution module receives and follows this route, controlling the vehicle to perform the cloud-based parking operation, thereby completing the parking process.

[0064] In this implementation, when the vehicle's autonomous capabilities are limited, it seamlessly switches to the remote driving control subsystem in the cloud for route replanning and decision-making. By utilizing the cloud's more powerful computing power and global information, it effectively overcomes local complex environments and significantly improves the overall success rate and system robustness of parking tasks on complex open roads.

[0065] In some optional implementations of this embodiment, the vehicle-side intelligent agent is further configured to send a remote docking request to the remote driving control subsystem in response to the failure of the autonomous vehicle to perform a cloud-based docking operation. The remote driving control subsystem is further configured to respond to the cloud-based docking request and, based on the received remote control instructions for the autonomous vehicle, control the autonomous vehicle to perform a remote docking operation.

[0066] In open road scenarios, when the cloud-based parking route issued by the remote driving control subsystem fails to complete the cloud-based parking operation and reports a failure due to drastic changes in the road environment during command execution (e.g., other vehicles suddenly intruding into the path, or the establishment of temporary traffic control), the vehicle-side intelligent system will immediately detect the failure.

[0067] Subsequently, the vehicle-side intelligent agent generates an upgraded remote docking request, which includes the vehicle's real-time status, environmental perception snapshots, and detailed failure context. This request is then sent to the remote driving control subsystem via a high-priority channel to request a cloud-based human operator to remotely control the autonomous vehicle.

[0068] Upon receiving the request, the remote driving control subsystem automatically creates and pops up a remote control session interface, connecting to a cloud-based human operator's seat. Through this interface, the operator can observe the vehicle's 360-degree surround-view video, sensor data, and scene analysis results in real time, and generate remote control commands specific to the vehicle by operating the steering wheel and accelerator / brake simulator.

[0069] These remote control commands are encoded in real time by the remote driving control subsystem and securely streamed to the vehicle. The vehicle-side control execution module receives and directly executes these real-time control commands from the cloud, precisely controlling the vehicle's steering, acceleration, and braking, thereby completing remote parking operations driven directly by a human.

[0070] In this implementation, in the extreme case where both the automated system (vehicle-side and cloud-side) fails, a final manual remote takeover is activated as a backup. Through the real-time judgment and control of the human operator, the vehicle can be forced into a safe parking state in any complex and dynamic open road environment, thus achieving a high level of safety assurance.

[0071] In some optional implementations of this embodiment, the road scenario includes a closed road scenario. A closed road scenario refers to a driving environment with the following core characteristics: the entire road or its main body is physically isolated (e.g., by guardrails or green belts), there are no at-grade intersections, and vehicles can only enter and exit through specific ramps or entrances / exits; the traffic flow is continuous, unidirectional, and consists of a relatively homogeneous flow of motor vehicles; at the same time, according to relevant regulations, vehicles are generally prohibited from stopping or parking arbitrarily in the driving lanes on such roads, and emergency stops must also follow strict regulations. In such scenarios, vehicle parking behavior is greatly restricted, the core objective is to quickly and safely escape the main traffic flow, and there is usually no freedom to choose a parking space.

[0072] For example, typical closed road scenarios include the main sections of highways, urban expressways, and fully enclosed elevated roads. For instance, an intercity highway with a design speed of over 100 km / h, a central median, fully controlled entrances and exits, and a ban on pedestrians and non-motorized vehicles falls under the category of a closed road scenario. The core strategy for triggering a stoppage on such roads is to prioritize the safety of traffic on the main road within the vehicle's current trajectory, achieving rapid deceleration and a safe stop.

[0073] In this implementation, the vehicle-side control execution module is further used to: respond to the autonomous vehicle being in a closed road scenario, and control the autonomous vehicle to perform a vehicle-side parking operation according to the autonomous vehicle's planned route.

[0074] As an example, after determining that the vehicle is in a closed road scenario and receiving a stop command, the vehicle-side control execution module immediately adopts a dedicated stopping strategy that matches the characteristics of this scenario. It does not perform operations such as searching for roadside parking spaces or planning complex lane-changing routes, but directly initiates the emergency stopping process based on the vehicle's current planned route (i.e., the main driving path generated by the navigation system when the vehicle enters autonomous driving mode).

[0075] The vehicle-side control module first controls the vehicle to brake quickly and smoothly to a stop at the roadside within its current lane, according to a preset deceleration curve. Throughout the braking process, the vehicle-side control module makes fine adjustments through the steering system to ensure the vehicle moves safely from near the center of the lane towards the roadside, maintaining driving stability and avoiding interference with adjacent vehicles. The vehicle will continue to decelerate along its planned route until it safely comes to a stop at the roadside. After stopping, the module immediately activates the hazard warning lights (double flashers) to warn vehicles behind.

[0076] In this implementation, considering the characteristic of closed roads where arbitrary lane changes and stops are prohibited, the vehicle-side control execution module adopts a strategy of slow braking to a stop along the original planned route, which realizes rapid and safe stopping in high-speed continuous flow, minimizing the interference of the stopping process on the main line traffic and the resulting safety risks.

[0077] In some optional implementations of this embodiment, in a closed road scenario, the vehicle-side control operation module maintains the entire parking process within the operation and control system. Specifically, the vehicle-side control execution module is also used to send a cloud-based parking request to the remote driving control subsystem in response to a failure of the autonomous vehicle to perform a vehicle-side parking operation.

[0078] The remote driving control subsystem is further used to: respond to cloud-based docking requests and generate cloud-based docking routes; and control autonomous vehicles to perform cloud-based docking operations based on the cloud-based docking routes.

[0079] As an example, in a closed road scenario, when the vehicle-side control execution module attempts to perform a vehicle-side parking operation (i.e., slowly braking along the current lane to the side of the road) according to the planned route, but fails to safely complete parking within the lane due to a sudden road obstacle (such as a falling object in front) or a deviation in the vehicle's own execution system, the vehicle-side control execution module will immediately determine that the vehicle-side parking operation has failed.

[0080] Subsequently, the vehicle-side control execution module encapsulates information such as the current vehicle status, precise location, and reason for failure, forming a structured cloud-based docking request, which is then sent directly to the remote driving control subsystem.

[0081] Upon receiving a request, the remote driving control subsystem recalculates the global path based on its real-time access to a high-precision map of the entire road network, traffic event information, and the vehicle's real-time status. In response to regulations prohibiting prolonged parking in the main lanes of closed roads, it may generate a cloud-based parking route, guiding the vehicle to the nearest permitted parking area, such as an emergency stopping lane, under controllable conditions.

[0082] Finally, the remote driving control subsystem sends this cloud-based parking route as a control command to the vehicle-side control execution module. Following this path, the vehicle-side control execution module controls the vehicle to perform the cloud-based parking operation, ultimately safely arriving at and parking in the designated area in the cloud.

[0083] This implementation provides crucial cloud-based replanning capabilities for failed stops on closed roads, guiding vehicles away from dangerous main road areas and towards legally safe parking areas, fundamentally eliminating the major safety hazard of being forced to stop illegally in high-speed traffic.

[0084] In some optional implementations of this embodiment, in a closed road scenario, the vehicle-side control execution module is also used to send a remote docking request to the remote driving control subsystem in response to the failure of the autonomous vehicle to perform a cloud docking operation.

[0085] The remote driving control subsystem is further used to respond to cloud-based docking requests and, based on received remote control commands for the autonomous vehicle, control the autonomous vehicle to perform remote docking operations.

[0086] As an example, in a closed road scenario, when the vehicle-side control execution module attempts to execute a cloud-based parking operation based on the cloud-based parking route issued by the remote driving control subsystem, but fails to complete the operation due to a sudden serious anomaly in the path environment during the execution of the command (such as the target emergency parking lane being occupied or a sudden fog causing sensor failure), and determines that the operation has failed, the vehicle-side control execution module will immediately generate a remote parking request and send it to the remote driving control subsystem.

[0087] Upon receiving the request, the remote driving control subsystem quickly creates a high-priority remote control session, connecting to a human operator in the cloud. The operator comprehensively assesses the current critical highway environment using real-time transmitted panoramic video streams, radar point clouds, and vehicle status data, and generates real-time remote control commands via the remote driving console.

[0088] These remote control commands are encoded in real time by the remote driving control subsystem and securely transmitted to the vehicle. The vehicle-side control execution module receives and directly executes these commands, translating the human operator's steering, acceleration, and braking intentions into actual vehicle actions. This allows for remote parking operations to be completed under direct human control, ultimately placing the vehicle in a relatively safe state.

[0089] In this implementation, in the high-risk scenario of a closed highway, when all multi-level automated parking solutions fail, the vehicle is provided with the highest level of direct safety assurance by enabling the final manual remote real-time control, ensuring that major safety accidents can be avoided in the most extreme abnormal situations.

[0090] In some optional implementations of this embodiment, the vehicle-side intelligent agent is also used to: update the state of the autonomous vehicle to the stopped state during the response to the stop command, and synchronize the operating state in the operation control system; and update the state of the autonomous vehicle to the stopped state in response to the successful parking of the autonomous vehicle, and synchronize the stopped state in the operation control system.

[0091] Upon receiving a shutdown command from the cloud-based operations decision center, the vehicle-side intelligent agent immediately activates its internally maintained operations state machine. It first updates the vehicle's operational status from "operating" or "idle" to "shutdown." Then, through the vehicle-to-cloud communication module, the intelligent agent synchronizes this latest "shutdown" status information to the cloud in real time, enabling the cloud-based operations decision center and monitoring interface to immediately recognize that the vehicle has entered the shutdown process.

[0092] After the vehicle successfully completes its parking maneuver (whether via vehicle-side parking, cloud-based parking, or remote parking), the vehicle-side intelligent agent receives confirmation of successful completion from the vehicle-side control execution module. Subsequently, the vehicle-side intelligent agent activates the state machine to update the vehicle status from "in operation" to "out of service." Similarly, it immediately synchronizes this "out of service" status back to the entire operation control system via vehicle-to-cloud communication, thereby accurately marking the vehicle as safely stationary and out of operation in the cloud.

[0093] In this implementation, real-time bidirectional synchronization between the vehicle-side state machine and the cloud system enables global transparency and precise management of vehicle operation status, greatly improving fleet collaborative scheduling efficiency, remote monitoring effectiveness, and anomaly response speed, and ensuring closed-loop traceability of operation control commands.

[0094] In some optional implementations of this embodiment, the system further includes: an order management module, used to close currently incomplete operating orders for autonomous vehicles and stop dispatching operating order requests for autonomous vehicles.

[0095] When the cloud-based operations decision center issues a stop-operation order, and the vehicle-side intelligent agent updates the vehicle status to "stopped operation" and synchronizes it to the cloud, the order management module TC (Traffic Control) is immediately triggered and executed.

[0096] The order management module first queries and locates all currently incomplete operational orders (e.g., ongoing passenger trips) for a vehicle in the order database based on its unique identifier. For these orders, the module automatically invokes the order settlement and termination logic, marks their status as "terminated due to operational adjustments," and may process corresponding fees and notify passengers according to preset rules.

[0097] Next, the order management module sends a command to the order scheduler or dispatch engine within the system to add the target vehicle to the "pause dispatch" list. This operation ensures that the system immediately stops dispatching any new operational order requests to that vehicle until the vehicle's status returns to an operational state. The entire order closure and dispatch restriction process is completed automatically, and status changes are fed back to the monitoring interface of the operations control system in real time.

[0098] This implementation method automates and instantly clears passenger orders during service outages and accurately blocks future orders, avoiding resource waste and passenger experience degradation. It is a key automated step to ensure smooth operation, improve overall system efficiency, and enhance user experience.

[0099] In some optional implementations of this embodiment, the cloud-based operation decision center is further configured to send an operation recovery command to the vehicle-side control execution module in response to detecting that the autonomous vehicle is within its designed operating domain. The vehicle-side intelligent agent is also configured to update the state of the autonomous vehicle to an operational state and synchronize the operational state in the operation control system.

[0100] Continue to refer to Figure 4 The diagram illustrates the timeline of the operation recovery process. When the cloud-based operation decision center continuously analyzes and determines, through its access to external data sources (such as weather warning systems and traffic incident platforms) and vehicle-reported information, that an autonomous vehicle in a "discontinued state" has recovered to a level that meets the safety standards of the vehicle's designed operating domain, i.e., when the vehicle is back in the designed operating domain, it will automatically generate an operation recovery instruction and send it to the vehicle's on-board control execution module.

[0101] The vehicle-side control execution module transmits instructions to the vehicle-side intelligent agent. The vehicle-side intelligent agent responds to these instructions, driving its internally maintained operational state machine to update the vehicle status from "out of service" to "in operation." Subsequently, the vehicle-side intelligent agent synchronizes this latest "in operation" status to the cloud-based operation control system in real time via the vehicle-cloud communication link.

[0102] After the status is synchronized, the vehicle-side intelligent agent will coordinate with the vehicle-side control execution module to activate the autonomous driving system. If there are operational orders to be resumed before the vehicle stopped, the system will automatically plan a route and control the vehicle to continue the journey.

[0103] This implementation method achieves an automatic and rapid closed loop from shutdown to resumption of operation. It automatically triggers and executes the recovery process based on objective conditions, which greatly reduces the cost of manual monitoring and operation, and significantly improves the continuity of fleet operation, response speed and overall resource utilization efficiency.

[0104] In some optional implementations of this embodiment, the vehicle-side intelligent agent is also used to initiate the autonomous driving mode of the autonomous vehicle in conjunction with the vehicle-side control execution module.

[0105] Once the vehicle-side intelligent agent updates the vehicle status to "operational" and completes synchronization during the recovery process, it then begins the specific process of activating the autonomous driving mode. First, based on the current operational task requirements, the vehicle-side intelligent agent determines a destination (such as the destination of the resumed journey or the order destination) and uses this as a parameter to initiate a structured path planning request to the vehicle-side control execution module.

[0106] The vehicle-side control execution module responds to this request by executing a path planning algorithm based on the vehicle's current location, destination information, and real-time map data. It then calculates a feasible global driving route and feeds this route information back to the vehicle-side intelligent agent.

[0107] After confirming successful route planning, the vehicle-mounted intelligent agent immediately sends a start request to the vehicle-mounted control execution module. The vehicle-mounted control execution module responds to this request, automatically executing the vehicle readiness procedure, including shifting the vehicle into drive. Subsequently, the vehicle-mounted control execution module begins to automatically control the vehicle to travel along the planned route, thus completing the activation of the autonomous driving mode.

[0108] This implementation method enables a seamless and automated start-up from a shutdown state to the resumption of autonomous driving operations. Through clear inter-module request-response collaboration, it ensures the safety, reliability, and efficiency of the start-up process, greatly improving the automation level of operation recovery and system response speed.

[0109] In some optional implementations of this embodiment, the system further includes: a vehicle-side interaction module, used to interact with target objects in the autonomous vehicle based on the state of the autonomous vehicle.

[0110] When the autonomous vehicle's status is updated to "inactive" by the vehicle-side intelligent agent due to receiving a shutdown command, the vehicle-side interaction module is automatically triggered. Based on preset interaction logic, this module determines that the target object for the current interaction is the passengers inside the vehicle.

[0111] Subsequently, the vehicle-side interaction module executes the interactive program bound to the "out of service status" through the in-vehicle multimedia system. For example, it controls the in-vehicle display screen to show the outage notice and automatically plays a pre-recorded reassuring voice message through the audio system to inform passengers that the vehicle is making a safe stop and to guide them to prepare accordingly (such as fastening their seat belts and not getting out of the vehicle at will).

[0112] Throughout the entire shutdown and subsequent processing, the vehicle-side interaction module dynamically switches and executes corresponding interactive content (such as informing passengers that the vehicle has stopped safely, explaining the waiting arrangements, or notifying them that the trip will resume) based on real-time changes in the vehicle's status (e.g., "shut down," "shutdown failed," or "operation resumed"), thereby maintaining necessary communication with passengers.

[0113] In this implementation, through automated interaction on the vehicle side, passengers are provided with timely and accurate reassurance and guidance in key scenarios such as service disruptions, which effectively improves passengers' sense of security and experience, and significantly reduces the reliance on and pressure of human customer service intervention.

[0114] While implementing automated operation processes such as "one-click shutdown" and "one-click recovery" based on the above embodiments, this embodiment also involves a multi-layered and complementary anomaly handling mechanism. The core of this mechanism consists of two parts: "anomaly alert" and "forced reset," which aim to monitor, report, and intervene in real time special or extreme situations that may occur in the automated process and exceed the normal processing capacity, ensuring the final closed loop and safety net of the entire operation control process.

[0115] Continue to refer to Figure 5 The diagram illustrates the exception handling mechanism.

[0116] "Raising a hand" refers to the process by which a vehicle, during a shutdown or recovery process, proactively reports a specific signal (i.e., "raising a hand") to the cloud when it detects a specific abnormal situation that requires cloud or human intervention. This mechanism transforms the vehicle from a passive terminal executing commands into an intelligent node capable of proactively reporting problems and requesting assistance.

[0117] The trigger conditions for raising hands are predefined and integrated into the logic of the vehicle-side intelligent agent. For example, when a vehicle stops on a highway or elevated road, but the vehicle-side intelligent agent determines, based on location information, that it is still in a main road area where long-term parking is prohibited, a specific "raise hands for highway / elevated road parking" will be triggered. Similarly, if a passenger is detected left behind or has a special need for assistance during the parking process, a "raise hands for special needs in passenger-carrying scenarios" will be triggered.

[0118] Each type of hand-raising corresponds to a unique identifier and carries structured contextual information (such as vehicle ID, location, time, and anomaly description) to enable rapid identification and processing in the cloud.

[0119] The specific procedure for handling raised hands is as follows: When the vehicle-side intelligent agent triggers the hand-raising action, the information will be immediately reported to the cloud-based operation decision-making center.

[0120] Upon receiving a hand-raising signal, the cloud-based operations decision center activates the corresponding contingency plan based on the type of hand raised. For example, for a "hand raised while stopped on a highway or elevated road," the center will immediately generate a high-priority work order, notifying ground staff to move the vehicle on-site; simultaneously, it may attempt to remotely move the vehicle through the remote driving control subsystem to remove it from the high-risk area.

[0121] For passengers with special needs in passenger scenarios, the central system will notify the customer service system to intervene and proactively contact the passenger to reassure and guide them. The status and outcome of the entire process will eventually be fed back to the system and may affect the flow of the vehicle's state machine (e.g., from "out of service" to "awaiting ground staff handling").

[0122] Forced reset is a high-priority proactive intervention method controlled by the cloud. When the cloud-based operations decision-making center discovers through monitoring that a vehicle's shutdown or recovery process has entered an unexpected deadlock (such as a prolonged state machine stagnation or communication interruption leading to unresponsive commands), or in response to an emergency global command, it can bypass the vehicle's current state and directly issue a forced state reset command.

[0123] This mechanism is usually used as a last resort and is activated in the following situations: the vehicle state machine is abnormally stuck; the vehicle-cloud communication has been interrupted for a long time and then restored, but the vehicle status is seriously inconsistent with the cloud status; or the operator needs to immediately perform a unified status update for all vehicles due to special emergency.

[0124] Authorized operators can issue "forced shutdown" or "forced resumption" commands to target vehicles through the management interface of the cloud-based operations decision center. These commands have the highest priority and, once sent to the vehicle, the vehicle's intelligent agent must unconditionally receive and execute them. The actions performed include: interrupting any currently running processes, forcibly setting the operations state machine to the target state specified in the command (e.g., "shut down" or "operating"), and performing necessary initialization or safety operations bound to that state (e.g., disabling the driver, activating hazard lights, etc.).

[0125] Forced reset ensures that the cloud retains ultimate control over the vehicle's operational status in extreme software anomalies or communication failures, preventing the system from entering an uncontrollable intermediate state.

[0126] The abnormal reporting mechanism and the forced reset mechanism together constitute an abnormal handling system that combines "proactive reporting" and "proactive intervention." The former solves specific business abnormalities that the vehicle perceives but cannot resolve on its own; the latter solves fundamental faults such as process blockages or inconsistent states at the system level.

[0127] The two work together and are integrated with the aforementioned core processes to ensure the ability to detect and handle anomalies across the entire chain, from vehicles to the cloud and then to ground human services. This gives the "one-click shutdown" system extremely high robustness, security and completeness, enabling it to cope with various long-tail problems that may arise in real-world complex operating environments.

[0128] In some optional implementations of this embodiment, in the scenario of mass vehicle shutdown, if each vehicle independently selects a stop based solely on its local environment, it can easily lead to multiple vehicles densely parked in a local road segment (such as near an exit), forming a "clustering" phenomenon, which can severely congest traffic and may cause secondary accidents or hinder the passage of emergency vehicles. To solve this problem, the system is designed with a collaboratively optimized stop selection mechanism.

[0129] When a vehicle enters a "stopped" state, the vehicle-mounted intelligent system carries the specific trigger source type "stopped" and, based on the currently determined road scenario (such as closed or open), initiates a corresponding stop and pull-over request to the vehicle-mounted control execution module.

[0130] Upon receiving this request, the vehicle-side control execution module's processing logic varies depending on network conditions, aiming to achieve global optimization or local optimization: In a cloud-based collaborative mode with a stable network, the vehicle-side control execution module reports information such as the vehicle's unique identifier, real-time high-precision location, speed, and current planned route to a cloud-based collaborative scheduling service. This service aggregates and analyzes information on all vehicles that have initiated stop requests within the same area and at the current time. Based on the overall road network conditions, and with the core objective of "avoiding local clustering and achieving balanced distribution," it calculates and assigns a "suggested stop point" for each vehicle. This calculation proactively avoids sensitive locations such as ramp merging areas and accident-prone areas, and ensures that the stopping positions between vehicles maintain a reasonable distance, thereby achieving "anti-crowding" optimization at the system level.

[0131] In the local backup mode when the network is unstable, if the vehicle cannot communicate stably with the cloud, the vehicle-side control execution module relies entirely on real-time perception data from the vehicle's sensors (such as LiDAR and vision cameras) to autonomously find and calculate the nearest safe stopping point (such as a non-intersection area with sufficient space on the side of the road) within the reachable area in front of the vehicle. This mode ensures basic safe stopping capability in the event of network anomalies.

[0132] Regardless of which of the above modes is used to obtain the "optimal stopping point," the vehicle-side control execution module will use this point as the final target, initiate a specific route planning request, generate a precise stopping trajectory, and control the vehicle to automatically drive to that point to complete the stop. This mechanism significantly reduces the risk of vehicle spatial distribution conflicts during mass shutdowns from the decision-making source.

[0133] In this embodiment, an operation control system for autonomous vehicles is provided. The cloud-based operation decision center is used to send a stop command to the vehicle-side control execution module of the autonomous vehicle in response to the detection that the autonomous vehicle is operating in an over-limit scenario. The vehicle-side control execution module is used to respond to the stop command and control the autonomous vehicle to perform a vehicle-side docking operation. The remote driving control subsystem is used to respond to the failure of the autonomous vehicle to perform a vehicle-side docking operation and control the autonomous vehicle to perform a cloud-based docking operation. This provides an automated operation control system that improves the operation control efficiency and operation safety in over-limit scenarios.

[0134] Please refer to Figure 6 , Figure 6 A flowchart illustrating an operation control method for an autonomous vehicle provided in this disclosure embodiment. Flowchart 600 includes the following steps: Step 601: Respond to the stop command for the autonomous vehicle and determine the current road scenario of the autonomous vehicle. Step 602: Adopt the stopping strategy corresponding to the road scenario and control the autonomous vehicle to perform a vehicle-side stopping operation. The above steps are applied to the vehicle-side control and operation module.

[0135] In some optional implementations of this embodiment, the road scenario includes an open road scenario. The aforementioned execution entity can perform step 602 as follows: First, in response to the autonomous vehicle being in an open road scenario, determine the parking position based on the current environment of the autonomous vehicle; then, generate a vehicle-side parking route from the current position of the autonomous vehicle to the parking position; finally, control the autonomous vehicle to perform a vehicle-side parking operation based on the vehicle-side parking route.

[0136] In some optional implementations of this embodiment, the road scenario includes an open road scenario. The aforementioned execution entity can perform step 602 as follows: First, in response to the autonomous vehicle being in an open road scenario, determine the parking position based on the current environment of the autonomous vehicle; then, obtain the vehicle-side parking route generated by the vehicle-side intelligent agent from the current position of the autonomous vehicle to the parking position; finally, control the autonomous vehicle to perform the vehicle-side parking operation based on the vehicle-side parking route.

[0137] In some optional implementations of this embodiment, the road scenario includes a closed road scenario. The above-mentioned execution entity can perform the above step 602 in the following manner: in response to the autonomous vehicle being in a closed road scenario, control the autonomous vehicle to perform vehicle-side parking operations according to the autonomous vehicle's planned route.

[0138] In some optional implementations of this embodiment, the aforementioned execution entity may also perform the following operations: in response to the failure of the autonomous vehicle to perform a vehicle-side docking operation, send a cloud-based docking request to the remote driving control subsystem; and control the autonomous vehicle to perform a remote docking operation according to the cloud-based docking route of the remote driving control subsystem.

[0139] In some optional implementations of this embodiment, the aforementioned execution entity may also perform the following operations: in response to the failure of the autonomous vehicle to perform a cloud-based docking operation, send a remote docking request to the remote driving control subsystem; and control the autonomous vehicle to perform a remote docking operation according to the remote control instructions of the remote driving control subsystem.

[0140] The above implementation methods can be implemented with reference to the relevant implementation methods in the operation and control system, and will not be repeated here.

[0141] This embodiment provides an operation control method for autonomous vehicles. In response to a stop command for an autonomous vehicle, the method determines the current road scenario in which the autonomous vehicle is located. By adopting a parking strategy corresponding to the road scenario, the method controls the autonomous vehicle to perform vehicle-side parking operations. By first identifying the road scenario and then matching the corresponding strategy, the method achieves scenario adaptation for parking control, which significantly improves the safety, compliance and success rate of automatic parking in complex road networks.

[0142] See also Figure 7 , Figure 7 This is a schematic diagram of an application scenario 700 of the operation control system for an autonomous vehicle according to this embodiment. During the operation of the autonomous vehicle 701, the cloud-based operation decision center 702 detects in real time whether the autonomous vehicle 701 is in an over-limit scenario. In response to detecting that the autonomous vehicle is operating in an over-limit scenario, it sends a stop command to the vehicle-side control execution module 703 of the autonomous vehicle. The vehicle-side control execution module responds to the stop command and controls the autonomous vehicle to perform a vehicle-side docking operation. In response to the failure of the autonomous vehicle to perform the vehicle-side docking operation, the remote driving control subsystem 704 controls the autonomous vehicle to perform a cloud-based docking operation.

[0143] Continue to refer to Figure 8 As an implementation of the methods shown in the above figures, this disclosure provides an embodiment of an operation control device for an autonomous vehicle, which is similar to... Figure 2 Corresponding to the method embodiments shown, the system can be specifically applied to various electronic devices.

[0144] like Figure 8As shown, the operation control device 800 for autonomous vehicles includes: a scenario determination unit 801, configured to respond to a stop command for the autonomous vehicle and determine the current road scenario in which the autonomous vehicle is located; and a docking unit 802, configured to adopt a docking strategy corresponding to the road scenario and control the autonomous vehicle to perform vehicle-side docking operations.

[0145] In some optional implementations of this embodiment, the road scenario includes an open road scenario, and the parking unit 802 is further configured to: in response to the autonomous vehicle being in an open road scenario, determine the parking position based on the current environment of the autonomous vehicle; generate a vehicle-side parking route from the current position of the autonomous vehicle to the parking position; and control the autonomous vehicle to perform a vehicle-side parking operation based on the vehicle-side parking route.

[0146] In some optional implementations of this embodiment, the road scenario includes an open road scenario, and the parking unit 802 is further configured to: in response to the autonomous vehicle being in an open road scenario, determine the parking position based on the current environment of the autonomous vehicle; then obtain the vehicle-side parking route from the current position of the autonomous vehicle to the parking position generated by the vehicle-side intelligent agent; and control the autonomous vehicle to perform the vehicle-side parking operation based on the vehicle-side parking route.

[0147] In some optional implementations of this embodiment, the road scenario includes a closed road scenario, and the docking unit 802 is further configured to: in response to the autonomous vehicle being in a closed road scenario, control the autonomous vehicle to perform a vehicle-side docking operation according to the autonomous vehicle's planned route.

[0148] In some optional implementations of this embodiment, the above-mentioned docking unit 602 is further configured to: in response to the failure of the autonomous vehicle to perform a vehicle-side docking operation, send a cloud-based docking request to the remote driving control subsystem; and control the autonomous vehicle to perform a remote docking operation according to the cloud-based docking route of the remote driving control subsystem.

[0149] In some optional implementations of this embodiment, the docking unit 602 is further configured to: send a remote docking request to the remote driving control subsystem in response to the failure of the autonomous vehicle to perform a cloud-based docking operation; and control the autonomous vehicle to perform a remote docking operation according to the remote control instructions of the remote driving control subsystem.

[0150] In this embodiment, an operation control device for autonomous vehicles is provided. The scenario determination unit in the operation control device responds to the stop command for the autonomous vehicle and determines the road scenario in which the autonomous vehicle is currently located. The parking unit adopts the parking strategy corresponding to the road scenario and controls the autonomous vehicle to perform vehicle-side parking operations. By first identifying the road scenario and then matching the corresponding strategy, scenario adaptation of parking control is achieved, which significantly improves the safety, compliance and execution success rate of automatic parking in complex road networks.

[0151] According to embodiments of this disclosure, this disclosure also provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to implement the operation control method for an autonomous vehicle described in any of the above embodiments.

[0152] According to embodiments of this disclosure, this disclosure also provides a readable storage medium storing computer instructions that, when executed by a computer, enable the implementation of the operation control method for an autonomous vehicle described in any of the above embodiments.

[0153] This disclosure provides a computer program product that, when executed by a processor, can implement the operation control method for autonomous vehicles described in any of the above embodiments.

[0154] Figure 9 A schematic block diagram of an example electronic device 900 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0155] like Figure 9As shown, device 900 includes a computing unit 901, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 902 or a computer program loaded from storage unit 908 into random access memory (RAM) 903. RAM 903 may also store various programs and data required for the operation of device 900. The computing unit 901, ROM 902, and RAM 903 are interconnected via bus 904. Input / output (I / O) interface 905 is also connected to bus 904.

[0156] Multiple components in device 900 are connected to I / O interface 905, including: input unit 906, such as keyboard, mouse, etc.; output unit 907, such as various types of monitors, speakers, etc.; storage unit 908, such as disk, optical disk, etc.; and communication unit 909, such as network card, modem, wireless transceiver, etc. Communication unit 909 allows device 900 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0157] The computing unit 901 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 901 performs the various methods and processes described above, such as the operation control method for an autonomous vehicle. For example, in some embodiments, the operation control method for an autonomous vehicle can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 908. In some embodiments, part or all of the computer program can be loaded and / or installed on device 900 via ROM 902 and / or communication unit 909. When the computer program is loaded into RAM 903 and executed by the computing unit 901, one or more steps of the operation control method for an autonomous vehicle described above can be performed. Alternatively, in other embodiments, the computing unit 901 can be configured to perform the operation control method for an autonomous vehicle by any other suitable means (e.g., by means of firmware).

[0158] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0159] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable automated vehicle operation control device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0160] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0161] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0162] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0163] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, also known as cloud computing servers or cloud hosts, which are hosting products within the cloud computing service system to address the management difficulties and weak business scalability inherent in traditional physical hosts and Virtual Private Servers (VPS) services; they can also be servers for distributed systems or servers incorporating blockchain technology.

[0164] According to the technical solution of this disclosure, an operation control system for autonomous vehicles is provided. The cloud-based operation decision center is used to send a stop command to the vehicle-side control execution module of the autonomous vehicle in response to the detection that the autonomous vehicle is operating in an over-limit scenario. The vehicle-side control execution module is used to respond to the stop command and control the autonomous vehicle to perform a vehicle-side docking operation. The remote driving control subsystem is used to respond to the failure of the autonomous vehicle to perform a vehicle-side docking operation and control the autonomous vehicle to perform a cloud-based docking operation. This provides an automated operation control system that improves the operation control efficiency and operation safety in over-limit scenarios.

[0165] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution provided in this disclosure can be achieved, and this is not limited herein.

[0166] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. An operation control system for an autonomous vehicle, comprising: The cloud-based operation decision center is used to send a shutdown command to the vehicle-side control execution module of the autonomous vehicle in response to the detection that the autonomous vehicle is operating in an excessive scenario. The vehicle-side control execution module is used to respond to the stop command and control the autonomous vehicle to perform a vehicle-side parking operation; The remote driving control subsystem is used to control the autonomous vehicle to perform a cloud-based parking operation in response to the failure of the autonomous vehicle to perform the on-board parking operation.

2. The system according to claim 1, wherein, The vehicle-side control execution module is further used for: In response to the shutdown command, determine the current road scenario in which the autonomous vehicle is located; The autonomous vehicle is controlled to perform the vehicle-side parking operation by adopting the parking strategy corresponding to the road scenario.

3. The system according to claim 2, wherein, The road scenarios include open road scenarios, and The vehicle-side control execution module is further used for: In response to the autonomous vehicle being in the open road scenario, a parking position is determined based on the current environment of the autonomous vehicle; Generate the vehicle-side parking route from the current location of the autonomous vehicle to the parking location; Based on the vehicle-mounted parking route, control the autonomous vehicle to perform the vehicle-mounted parking operation.

4. The system according to claim 2, wherein, The road scenarios include open road scenarios, and The vehicle-side control execution module is further used for: In response to the autonomous vehicle being in the open road scenario, a parking position is determined based on the current environment of the autonomous vehicle; as well as The system also includes: The vehicle-side intelligent agent is used to generate the vehicle-side parking route from the current location of the autonomous vehicle to the parking location. as well as The vehicle-side control execution module is further used for: Based on the vehicle-mounted parking route, control the autonomous vehicle to perform the vehicle-mounted parking operation.

5. The system according to claim 3 or 4, wherein, The vehicle-side intelligent agent is also used for: In response to the failure of the autonomous vehicle to perform the on-board docking operation, a cloud-based docking request is sent to the remote driving control subsystem; The remote driving control subsystem is further used for: In response to the cloud docking request, generate a cloud docking route; Based on the cloud-based parking route, control the autonomous vehicle to perform a cloud-based parking operation.

6. The system according to claim 5, wherein, The vehicle-side intelligent agent is also used for: In response to the failure of the autonomous vehicle to perform the cloud-based docking operation, a remote docking request is sent to the remote driving control subsystem; The remote driving control subsystem is further used for: In response to the cloud-based docking request, and based on the received remote control instructions for the autonomous vehicle, the system controls the autonomous vehicle to perform a remote docking operation.

7. The system according to claim 2, wherein, The road scenarios include closed road scenarios, and The vehicle-side control execution module is further used for: In response to the autonomous vehicle being in the closed road scenario, the autonomous vehicle is controlled to perform the vehicle-side parking operation according to the planned route of the autonomous vehicle.

8. The system according to claim 7, wherein, The vehicle-side control execution module is also used for: In response to the failure of the autonomous vehicle to perform the on-board docking operation, a cloud-based docking request is sent to the remote driving control subsystem; The remote driving control subsystem is further used for: In response to the cloud docking request, generate a cloud docking route; Based on the cloud-based parking route, control the autonomous vehicle to perform a cloud-based parking operation.

9. The system according to claim 7, wherein, The vehicle-side control execution module is also used for: In response to the failure of the autonomous vehicle to perform the cloud-based docking operation, a remote docking request is sent to the remote driving control subsystem; The remote driving control subsystem is further used for: In response to the cloud-based docking request, and based on the received remote control instructions for the autonomous vehicle, the system controls the autonomous vehicle to perform a remote docking operation.

10. The system according to any one of claims 1-9, wherein, Vehicle-side intelligent agents are also used for: In response to the shutdown command, the status of the autonomous vehicle is updated to a shutdown status, and the operational status is synchronized in the operation control system. In response to the successful docking of the autonomous vehicle, the status of the autonomous vehicle is updated to "discontinued" and the "discontinued" status is synchronized in the operation control system.

11. The system according to any one of claims 1-9, wherein, Also includes: The order management module is used to close any currently incomplete operating orders for the autonomous vehicle and to stop dispatching operating order requests for the autonomous vehicle.

12. The system according to any one of claims 1-9, wherein, The cloud-based operation decision-making center is also used for: In response to detecting that the autonomous vehicle is in a scenario within its designed operating domain, an operation recovery command is sent to the vehicle-side control execution module; The vehicle-side intelligent agent is also used for: The status of the autonomous vehicle is updated to "operational" and the "operational" status is synchronized in the operation control system.

13. The system according to any one of claims 12, wherein, The vehicle-side intelligent agent is also used for: The autonomous driving mode of the autonomous vehicle is activated by combining the vehicle-side control execution module.

14. The system according to any one of claims 1-9, wherein, Also includes: The vehicle-side interaction module is used to interact with target objects in the autonomous vehicle based on the state of the autonomous vehicle.

15. An operation control method for an autonomous vehicle, comprising: In response to a stop command for an autonomous vehicle, determine the current road scenario in which the autonomous vehicle is located; The autonomous vehicle is controlled to perform the vehicle-side parking operation by adopting the parking strategy corresponding to the road scenario.

16. The method according to claim 15, wherein, The road scenarios include open road scenarios, and The step of using the parking strategy corresponding to the road scenario to control the autonomous vehicle to perform the vehicle-side parking operation includes: In response to the autonomous vehicle being in the open road scenario, a parking position is determined based on the current environment of the autonomous vehicle; Generate the vehicle-side parking route from the current location of the autonomous vehicle to the parking location; Based on the vehicle-mounted parking route, control the autonomous vehicle to perform the vehicle-mounted parking operation.

17. The method according to claim 15, wherein, The road scenarios include open road scenarios, and The step of using the parking strategy corresponding to the road scenario to control the autonomous vehicle to perform the vehicle-side parking operation includes: In response to the autonomous vehicle being in the open road scenario, a parking position is determined based on the current environment of the autonomous vehicle; Obtain the vehicle-side parking route from the current location of the autonomous vehicle to the parking location, generated by the vehicle-side intelligent agent; Based on the vehicle-mounted parking route, control the autonomous vehicle to perform the vehicle-mounted parking operation.

18. The method according to claim 15, wherein, The road scenarios include closed road scenarios, and The step of using the parking strategy corresponding to the road scenario to control the autonomous vehicle to perform the vehicle-side parking operation includes: In response to the autonomous vehicle being in the closed road scenario, the autonomous vehicle is controlled to perform the vehicle-side parking operation according to the planned route of the autonomous vehicle.

19. The method according to claim 18, wherein, Also includes: In response to the failure of the autonomous vehicle to perform the on-board docking operation, a cloud-based docking request is sent to the remote driving control subsystem; Based on the cloud-based parking route of the remote driving control subsystem, the autonomous vehicle is controlled to perform a remote parking operation.

20. The method according to claim 19, wherein, Also includes: In response to the failure of the autonomous vehicle to perform the cloud-based docking operation, a remote docking request is sent to the remote driving control subsystem; According to the remote control commands of the remote driving control subsystem, the autonomous vehicle is controlled to perform a remote parking operation.

21. An operation control device for an autonomous vehicle, comprising: The scene determination unit is configured to respond to a stop command for an autonomous vehicle and determine the road scene in which the autonomous vehicle is currently located. The docking unit is configured to adopt the docking strategy corresponding to the road scenario and control the autonomous vehicle to perform the vehicle-side docking operation.

22. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 15-20.

23. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 15-20.

24. A computer program product comprising: A computer program that, when executed by a processor, implements the method according to any one of claims 15-20.