Methods and systems for controlling work vehicles, electronic devices, storage media

By acquiring the operational status and physical sensing data of the working equipment, and dynamically determining the safety confidence level based on cross-validation of dual-source data, the risk of misjudgment caused by a single data source in the existing technology is solved, thereby improving the safety of the working vehicle operation process.

CN122086007APending Publication Date: 2026-05-26ZHEJIANG GEELY HLDG GRP CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG GEELY HLDG GRP CO LTD
Filing Date
2026-02-10
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

In existing technologies, safety strategies for work vehicles rely on a single data source during operation, leading to a high risk of misjudgment, an inability to intervene in the work process in advance, and an inability to effectively prevent potential dangers, thus posing safety hazards.

Method used

By acquiring the operating status and physical sensing data of the working equipment, and based on cross-validation of dual-source data, the safety confidence level is dynamically determined, and working instructions or non-working instructions are dynamically issued to achieve precise control of the working process.

Benefits of technology

It effectively avoids the risk of misjudgment from a single data source, blocks potential dangers in advance, improves the safety of the operation process, and ensures the orderly progress of the operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122086007A_ABST
    Figure CN122086007A_ABST
Patent Text Reader

Abstract

This application provides a method, system, electronic device, and storage medium for controlling a work vehicle to improve the safety of the work process. The method includes: obtaining the current operating status of the work equipment during operation; obtaining physical sensing data associated with the work process; determining a safety confidence level based on the degree of matching between the operating status and the physical sensing data; issuing a work instruction to the work vehicle when the safety confidence level is greater than or equal to a confidence threshold, the work instruction being used to control the work vehicle's operation; and issuing a non-work instruction to the work vehicle when the safety confidence level is less than the confidence threshold, the non-work instruction being used for early warning and / or protection of the work vehicle. Thus, through cross-validation of dual-source data and dynamic instruction determination, the risk of misjudgment that may arise from a single data source is effectively avoided, and potential dangers are proactively blocked from the source of the work instruction, which is conducive to further improving the safety of the work process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle technology, and more particularly to a method and system for controlling work vehicles, electronic devices, and storage media. Background Technology

[0002] In port and other similar operational scenarios, work vehicles and equipment need to work together to perform tasks such as material handling. Currently, most safety strategies in these technologies rely on passive protective measures such as obstacle detection by a single vehicle combined with emergency braking. Essentially, these are last-minute remedial measures after an accident has occurred. They can only respond to emergencies after danger has materialized, and cannot intervene in the operational process beforehand. For example, if the lifting equipment's spreader is not completely detached from the container, the unmanned truck may not be aware of this critical operational status and may continue driving according to preset instructions. Existing safety strategies can only activate braking when a collision risk is imminent, and cannot identify and prevent dangerous operations during the initial issuance of operational instructions. Therefore, the safety of these technologies in operational processes needs improvement. Summary of the Invention

[0003] This application provides a method and system for controlling work vehicles, electronic devices, and storage media to improve the safety of the work process.

[0004] This application provides a method for controlling a work vehicle, comprising: obtaining the current operating status of the work equipment during operation; obtaining physical sensing data associated with the operation process; determining a safety confidence level based on the degree of matching between the operating status and the physical sensing data; issuing a work instruction to the work vehicle when the safety confidence level is greater than or equal to a confidence level threshold, the work instruction being used to control the operation of the work vehicle; and issuing a non-work instruction to the work vehicle when the safety confidence level is less than the confidence level threshold, the non-work instruction being used for early warning and / or protection of the work vehicle.

[0005] Optionally, a safety confidence level is determined based on the degree of matching between the operation status and the physical sensing data, including: determining a baseline safety confidence level based on the degree of matching between the operation status and the physical sensing data; determining a correction factor based on the degree of matching at historical moments and / or the operation environment in which the current operation process is located; and determining a safety confidence level based on the baseline safety confidence level and the correction factor.

[0006] Optionally, the correction factor is determined based on the matching degree at historical moments, including: determining the data reliability of the matching degree based on the matching degree at multiple historical moments and the verification results of the matching degree at multiple historical moments; and determining the correction factor based on the data reliability.

[0007] Optionally, the correction factor is positively correlated with the data confidence level; the safety confidence level is determined based on the baseline safety confidence level and the correction factor, including: determining the product of the baseline safety confidence level and the correction factor as the safety confidence level; or, determining the sum of the baseline safety confidence level and the correction factor as the safety confidence level.

[0008] Optionally, the operating environment includes external environmental risk data and / or internal device health data; based on the operating environment in which the current operation is performed, a correction factor is determined, including: determining the correction factor based on external environmental risk data and / or internal device health data.

[0009] Optionally, the correction factor is negatively correlated with the severity of the external environmental risk as represented by the external environmental risk data; the correction factor is positively correlated with the health level as represented by the internal device health data; the safety confidence level is determined based on the baseline safety confidence level and the correction factor, including: determining the product of the baseline safety confidence level and the correction factor as the safety confidence level; or, determining the sum of the baseline safety confidence level and the correction factor as the safety confidence level.

[0010] Optionally, issuing non-operation instructions to the work vehicle includes: determining, among multiple levels of non-operation instructions, a target non-operation instruction corresponding to the value of the safety confidence level, and issuing the target non-operation instruction.

[0011] This application provides a method for controlling a work vehicle, comprising: receiving a field-end command issued by a field-end control unit; the field-end command includes a work command or a non-work command, wherein the work command and the non-work command are generated by executing any of the aforementioned methods; performing real-time verification on local sensors to obtain local verification results; and determining whether the local verification results are consistent with the work intention of the field-end command to determine whether to execute the field-end command.

[0012] Optionally, determining whether the local verification result is consistent with the operational intent of the field-end command to decide whether to execute the field-end command includes: [determining whether the local verification result is consistent with the operational intent of the field-end command]. Figure 1 When the local verification result is inconsistent with the operational intent of the field command, the control vehicle shall not execute the field command.

[0013] This application provides an electronic device including one or more processors for performing any of the foregoing methods for controlling a work vehicle.

[0014] This application provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the method for controlling a work vehicle as described above.

[0015] This application provides a system for controlling a work vehicle, comprising: a machine-side coordination unit for reporting the current operating status of the work equipment during operation; a vehicle-side execution unit for reporting physical sensing data associated with the operation process; the work vehicle including at least a portion of the vehicle-side execution unit; and a field-side control unit for determining a safety confidence level based on the degree of matching between the operating status and the physical sensing data; issuing a work instruction to the vehicle-side execution unit when the safety confidence level is greater than or equal to a confidence level threshold, thereby controlling the work vehicle to execute the work instruction, the work instruction being used to control the work vehicle's operation; and issuing a non-operation instruction to the vehicle-side execution unit when the safety confidence level is less than the confidence level threshold, the non-operation instruction being used for early warning and / or protection of the work vehicle.

[0016] The method, system, electronic device, and storage medium provided in this application for controlling work vehicles acquire the work status during the operation of the work equipment to clarify the current progress of the work, and collect physical sensing data of the work process to reflect objective data feedback of the actual work scenario. The two types of information are linked. The safety confidence level is quantified based on the degree of matching between the work status and the physical sensing data, enabling accurate judgment of the actual completion of the work and effectively avoiding the misjudgment problem that easily occurs in existing technologies that rely solely on single status data. When the safety confidence level reaches the confidence level threshold, it indicates that the work status uploaded by the current terminal and the actual detected physical sensing data are relatively well matched, and issuing work instructions is relatively safe, ensuring the orderly progress of the work process. When the safety confidence level is less than the confidence level threshold, early warning or protective measures are activated through non-work instructions to avoid safety hazards caused by blindly executing work under unsafe conditions. In this way, through cross-validation of dual-source data and dynamic judgment of instructions, the risk of misjudgment that may be caused by a single data source is effectively avoided, and potential dangers are blocked in advance from the source of work instructions, which is conducive to further improving the safety of the work process. In this way, based on the comparison between the safety confidence level and the confidence threshold, work instructions or non-work instructions are dynamically issued. By cross-validating the data from two sources and dynamically judging the instructions, the risk of misjudgment that may be caused by a single data source is effectively avoided. Potential dangers are blocked in advance from the source of work instructions, which is conducive to further improving the safety of the work process. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of a system for controlling a work vehicle provided in one embodiment of this application; Figure 2 This is a flowchart illustrating a method for controlling a work vehicle according to an embodiment of this application; Figure 3 This is a flowchart illustrating a method for controlling a work vehicle according to another embodiment of this application; Figure 4This is a flowchart illustrating a method for controlling a work vehicle according to another embodiment of this application; Figure 5 This is a flowchart illustrating a method for controlling a work vehicle according to another embodiment of this application. Detailed Implementation

[0018] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings.

[0019] In port and other operational scenarios, work vehicles and equipment need to work together to perform tasks such as material handling. Most safety strategies during these operations rely on passive protection methods such as obstacle detection by a single vehicle combined with emergency braking. Essentially, these are last-minute remedial measures after an accident has occurred. They can only respond to emergencies after danger has materialized, and cannot intervene in the operational process beforehand. For example, if a crane's spreader is not completely detached from a container, an unmanned truck may continue driving according to preset instructions if it is unaware of this critical operational status. Existing safety strategies can only activate braking when a collision risk is imminent, and cannot identify and prevent the dangerous operation during the initial issuance of operational instructions. This passive protection mode not only has limited protective effectiveness but may also lead to equipment damage, cargo damage, and other safety accidents due to untimely braking, seriously affecting operational safety.

[0020] Combination Figure 1 As shown in the illustration, this application provides a system for controlling work vehicles, including a machine-side coordination unit 10, a vehicle-side execution unit 20, and a field-side control unit 30. Both the machine-side coordination unit 10 and the vehicle-side execution unit 20 are communicatively connected to the field-side control unit 30. The work vehicles and work equipment operate collaboratively, and one or more work vehicles and work equipment are provided. The work vehicles are, for example, unmanned container trucks, i.e., driverless container trucks. In other embodiments, the work vehicles can also be container transport vehicles, container tractors, etc. The work equipment is, for example, large machinery such as forklifts and gantry cranes.

[0021] The machine-side coordination unit 10 is used to report the current operating status of the working equipment during operation. This operating status is reported to the field-side control unit.

[0022] The vehicle-mounted execution unit 20 is used to report physical sensing data associated with the work process. The work vehicle includes at least a portion of the vehicle-mounted execution unit. This physical sensing data is reported to the field control unit.

[0023] The field control unit 30 is used to determine the safety confidence level based on the degree of matching between the operation status and the physical sensing data; when the safety confidence level is greater than or equal to the confidence level threshold, it sends an operation command to the vehicle execution unit to control the work vehicle to execute the operation command; when the safety confidence level is less than the confidence level threshold, it sends a non-operation command to the vehicle execution unit.

[0024] Among them, the safety confidence level is positively correlated with the degree of matching between the operation status and the physical perception data. That is, the better the matching between the operation status and the physical perception data, the higher the safety confidence level.

[0025] The system for controlling work vehicles provided in this application involves a machine-side coordination unit that reports the operational status of the work equipment in real time to clarify the current progress of the operation; and a vehicle-side execution unit that uploads physical sensing data associated with the operation process to reflect objective data feedback from the actual work scenario. Both types of information are centralized at the field control unit to form a linkage. The field control unit determines a quantifiable safety confidence level based on the degree of matching between the operational status and the physical sensing data. When the safety confidence level reaches a confidence threshold, it indicates that the operational status uploaded by the machine-side and the actual detected physical sensing data are relatively well-matched, making it relatively safe to issue work instructions and ensuring the orderly progress of the work process. When the safety confidence level is less than the confidence threshold, early warning or protective measures are activated through non-work instructions to avoid safety hazards caused by blindly executing work under unsafe conditions. In this way, through cross-validation of dual-source data and dynamic determination of instructions, the risk of misjudgment that may be caused by a single data source is effectively avoided, and potential dangers are blocked in advance from the source of work instructions, which is conducive to further improving the safety of the work process.

[0026] The field control unit 30 includes an ESC (Equipment Control System) interface 301, a work instruction system 302, and a risk fusion decision-maker 303. The machine-side coordination unit 10 and the vehicle-mounted execution unit 20 are both connected to the ESC interface 301. The work instruction system 302 is connected to the ESC interface 301. The risk fusion decision-maker 303 is connected between the work instruction system 302 and the ESC interface 301. The vehicle-mounted execution unit 20 includes a vehicle-mounted fusion perception system 201, a vehicle-mounted safety controller 202, and a drive-by-wire chassis 203. The vehicle-mounted safety controller 202 is connected to the drive-by-wire chassis 203, which is the final executor of the work instructions. Both the vehicle-mounted fusion perception system 201 and the vehicle-mounted safety controller 202 are connected to the ESC interface 301.

[0027] The vehicle-mounted fusion perception system 201 reports physical perception data associated with the operation process to the ESC interface 301. In at least some embodiments, the vehicle-mounted fusion perception system 201 is used to acquire and report physical perception data associated with the operation process. Specifically, the vehicle-mounted fusion perception system 201 includes a sensor system. The sensor system is equipped with multi-mode sensors, such as vision sensors, lidar sensors, and integrated navigation systems. Further, the vision sensor is, for example, a high-resolution vision camera, which can identify visual separation gaps between the spreader lock head and the container corner fittings that exceed a set threshold. The lidar sensor can detect physical separation states where the Euclidean distance between the spreader and container point cloud clusters is greater than 0.2 meters and there is no continuous point cloud bridging. The vehicle-mounted fusion perception system collects raw information through the sensor system, then performs local preprocessing on the raw information, extracts key features, and uploads them to the field control unit. The key features uploaded to the field control unit are the aforementioned physical perception data. The key features are adaptively adjusted according to different operation processes.

[0028] As a key risk source and collaborator, the machine-side coordination unit 10's main function is to reliably report its own precise position and orientation, the locking status of the spreader / fork tines, and the container's landing / suspending status to the field control unit, forming the logical input for collaborative safety.

[0029] In some embodiments, the vehicle-mounted safety controller 202 ultimately executes an arbitration mechanism. Specifically, the field control unit determines the field command, which may be an operational command or a non-operational command depending on the actual situation. After the field control unit determines the field command, the vehicle-mounted execution unit does not execute it directly, but instead initiates a local final arbitration mechanism. Specifically, after executing any command for controlling movement, the vehicle-mounted safety controller calls local sensors for a final real-time verification. This verification process is often in the millisecond range. Only when the local verification result matches the safety intent of the field command... Figure 1 When this occurs, the field-end safety controller further issues field-end commands to the drive-by-wire chassis for execution. If the local verification result is inconsistent with the safety intent of the field-end command, the verification fails. For example, if the field-end command indicates permission for the vehicle to leave, but no physical connection is detected locally, the vehicle-mounted safety controller will refuse to execute the operation command and issue an alarm, thus achieving active protection at the vehicle end. In some embodiments, when communication is interrupted, the vehicle-mounted safety controller controls the work vehicle to enter a safe parking state to achieve self-rescue. Specifically, it enters this safe parking state based on the last valid command and the vehicle's own perception. Safety is ensured through a failure mechanism.

[0030] In some embodiments, the system for controlling work vehicles is applied in port scenarios.

[0031] Combination Figure 2As shown, this application embodiment provides a method for controlling a work vehicle, including steps S11 to S15.

[0032] Step S11: During the operation of the working equipment, obtain the current operating status of the working equipment.

[0033] In some embodiments, the job status here refers to the job completion status, i.e., the most recently completed job.

[0034] Step S12: Obtain physical sensing data associated with the operation process.

[0035] Physical sensing data includes parameters such as the position of the work vehicle, the relative positional relationship and connection between the work vehicle and the target object, the relative positional relationship and connection between the work equipment and the target object, and the current position of the target object, as well as one or more of the relative positional relationships between the work vehicle and the work equipment. The target object is the object of the operation process, such as a moving container. In other embodiments, physical sensing data may also include other data associated with the operation process, such as the presence and location distribution of personnel in the scenario. Different types of physical sensing data can be set for different operation processes, which will not be listed here.

[0036] Step S13: Determine the safety confidence level based on the degree of matching between the operation status and the physical sensing data.

[0037] Step S14: If the safety confidence level is greater than or equal to the confidence level threshold, a work instruction is issued to the work vehicle. The work instruction is used to control the work vehicle to operate.

[0038] During implementation, the confidence threshold here can be set according to actual needs.

[0039] Step S15: If the safety confidence level is less than the confidence level threshold, issue a non-operation instruction to the work vehicle. The non-operation instruction is used for early warning and / or protection of the work vehicle.

[0040] The non-operational instructions here include at least one of the following: issuing an alarm instruction, issuing a prohibition instruction indicating that the work vehicle is prohibited from performing operations, and a preset protective instruction.

[0041] The method for controlling work vehicles provided in this application acquires the work status during the operation of the work equipment to clarify the current progress of the work, and collects physical sensing data of the work process to reflect objective data feedback of the actual work scenario. The two types of information are linked. The safety confidence level is quantified based on the matching degree between the work status and the physical sensing data, enabling accurate judgment of the actual completion of the work and effectively avoiding the misjudgment problem that easily occurs when relying on only a single status data in existing technologies. When the safety confidence level reaches the confidence level threshold, it indicates that the work status uploaded by the current terminal and the actual detected physical sensing data are relatively well matched, and issuing work instructions is relatively safe, ensuring the orderly progress of the work process. When the safety confidence level is less than the confidence level threshold, early warning or protective measures are activated through non-work instructions to avoid safety hazards caused by blindly executing work under unsafe conditions. In this way, through cross-validation of dual-source data and dynamic judgment of instructions, the risk of misjudgment that may be caused by a single data source is effectively avoided, and potential dangers are blocked in advance from the source of work instructions, which is conducive to further improving the safety of the work process. In this way, based on the comparison between the safety confidence level and the confidence threshold, work instructions or non-work instructions are dynamically issued. By cross-validating the data from two sources and dynamically judging the instructions, the risk of misjudgment that may be caused by a single data source is effectively avoided. Potential dangers are blocked in advance from the source of work instructions, which is conducive to further improving the safety of the work process.

[0042] Here, an exemplary explanation is provided for the aforementioned work instructions. In some embodiments, work instructions include one or more of the following: dynamic electronic fence, access permit, and speed limit instruction. Specifically, for the work instruction corresponding to the dynamic electronic fence, the generation unit is the risk fusion decision-maker at the site, the recipient is the vehicle-mounted safety controller of all relevant work vehicles, and the core execution action is that the path planning system avoids the virtual area in real time, ultimately achieving the design purpose of preventatively delineating risk areas and realizing physical isolation; for the work instruction corresponding to the access permit, the generation unit is the risk fusion decision-maker at the site, the recipient is the vehicle-mounted safety controller of a specific work vehicle, and the core execution action is that the permit is used as an authorization credential for the vehicle to perform key work actions such as leaving, ultimately achieving the design purpose of precise access control with one vehicle per instruction; for the work instruction corresponding to the speed limit instruction, the generation unit is the risk fusion decision-maker or work instruction system at the site, the recipient is a specific work vehicle or all work vehicles in a certain area, and the core execution action is that the drive-by-wire chassis uses the value contained in the instruction as the current maximum speed limit, ultimately achieving the design purpose of adjusting vehicle speed according to risk and reducing the severity of accidents through dynamic constraints.

[0043] In at least some embodiments, the aforementioned method is applied to the aforementioned system, in combination with Figure 3As shown, this application embodiment provides a method for controlling a work vehicle, including steps S110 to S150.

[0044] In step S110, the machine-side coordination unit reports the current operating status of the working equipment to the field-side control unit during the operation of the working equipment.

[0045] In some embodiments, the job status here refers to the job completion status, i.e., the most recently completed job.

[0046] In step S120, the vehicle-side execution unit reports the physical sensing data associated with the operation process to the field-side control unit.

[0047] In step S130, the field control unit determines the safety confidence level based on the degree of matching between the operation status and the physical sensing data.

[0048] Specifically, the risk fusion decision-maker determines the safety confidence level based on the degree of matching between the operational status and physical perception data.

[0049] In step S140, when the safety confidence level is greater than or equal to the confidence level threshold, the field control unit sends a work instruction to the vehicle execution unit. The work instruction is used to control the operation of the work vehicle.

[0050] During implementation, the confidence threshold here can be set according to actual needs.

[0051] In step S150, if the safety confidence level is less than the confidence level threshold, the field control unit issues a non-operation command to the vehicle execution unit. The non-operation command is used for early warning and / or protection of the working vehicle.

[0052] In some embodiments, determining the safety confidence level based on the degree of matching between the job status and physical sensing data includes: determining the safety confidence level solely based on the degree of matching between the job status and physical sensing data. A pre-defined data correspondence between different degrees of matching between the job status and physical sensing data and their corresponding safety confidence levels is established. The degree of matching is determined based on the current job status and physical sensing data, and then the corresponding safety confidence level is further determined. This makes the judgment logic simpler and clearer, eliminating the need for complex data fusion or correction processes, and allowing for rapid output of judgment results, thus improving the response efficiency of command issuance. The degree of matching can be categorized, for example, as highly consistent, generally consistent, slightly conflicting, and severely conflicting. For instance, a state consistency mapping table can be established to assign a corresponding safety confidence level value to each degree of matching, i.e., conflict type. A value of 1.2 corresponds to a highly consistent match, where logical and physical information corroborate each other, resulting in a high level of security confidence. A value of 1.0 corresponds to a generally consistent match. A value of 0.5 to 0.8 corresponds to a minor conflict in the match, where the confidence level is weakened due to information ambiguity. A value of 0.1 to 0.3 corresponds to a severe conflict in the match, where the two sources of information are fundamentally contradictory, significantly weakening the confidence level below the security threshold and inevitably triggering intervention. The specific values ​​used during implementation can be jointly determined by domain experts based on the severity of the incident's consequences, the probability of the conflict occurring, and the reliability requirements of the process.

[0053] Combination Figure 4 As shown, this application embodiment provides a method for controlling a work vehicle, including steps S11 to S15.

[0054] Step S11: During the operation of the working equipment, obtain the current operating status of the working equipment.

[0055] In some embodiments, the job status here refers to the job completion status, i.e., the most recently completed job.

[0056] Step S12: Obtain physical sensing data associated with the operation process.

[0057] Step S131: Determine the baseline safety confidence level based on the degree of matching between the operation status and the physical sensing data.

[0058] Step S132: Determine the correction factor based on the matching degree of historical time and / or the operating environment of the current operation.

[0059] Step S133: Determine the security confidence level based on the baseline security confidence level and the correction factor.

[0060] Step S14: If the safety confidence level is greater than or equal to the confidence level threshold, a work instruction is issued to the work vehicle. The work instruction is used to control the work vehicle to operate.

[0061] Step S15: If the safety confidence level is less than the confidence level threshold, issue a non-operation instruction to the work vehicle. The non-operation instruction is used for early warning and / or protection of the work vehicle.

[0062] The final safety confidence level is determined by combining a baseline safety confidence level with a correction factor, further optimizing the accuracy and adaptability of safety assessments. First, a baseline safety confidence level is determined based on the matching degree between the operational status and physical perception data, providing a foundation for safety assessments that are compatible with the current real-time operational situation. Then, a correction factor is introduced that is related to at least one of the matching degree at a historical moment and the current operational environment. This ensures that the calculation of safety confidence level is not limited to instantaneous data at a single time point, but combines at least one of historical operational experience and real-time environmental conditions to further calibrate the baseline safety confidence level. This makes the final safety confidence level more closely aligned with the complex needs of actual operational scenarios, improving the accuracy of safety confidence level, reducing the risk of misjudgment, and thus further enhancing operational safety. The matching degree can be categorized, for example, into highly consistent matching, generally consistent matching, slightly conflicting matching, and severely conflicting matching. For instance, a state consistency mapping table can be established to assign a corresponding baseline safety confidence level value to each matching degree, i.e., conflict type. A value of 1.2 corresponds to a highly consistent match, where logical and physical information corroborate each other, resulting in a high baseline security confidence level. A value of 1.0 corresponds to a generally consistent match. A value of 0.5 to 0.8 corresponds to a minor conflict in the match, where the confidence level is weakened due to information ambiguity. A value of 0.1 to 0.3 corresponds to a severe conflict in the match, where the two sources of information are fundamentally contradictory, significantly weakening the confidence level below the security threshold and inevitably triggering intervention. The specific values ​​used during implementation can be jointly determined by domain experts based on the severity of the incident's consequences, the probability of the conflict occurring, and the reliability requirements of the process.

[0063] Specifically, in some embodiments, the correction factor is determined based on the matching degree at historical moments, including: determining the data reliability of the matching degree based on the matching degree at multiple historical moments and the verification results of the matching degree at multiple historical moments; and determining the correction factor based on the data reliability. By determining the data reliability through the matching degree at multiple historical moments and the corresponding verification results, the determination of the correction factor has stable data support. This effectively filters out occasional matching deviations, accurately reflects the stability of the matching relationship between the operational status and the physical sensing data, thereby making the safety confidence level calibrated based on the correction factor more reliable, avoiding deviations in safety judgments due to short-term data fluctuations, providing a more stable decision-making basis for subsequent instruction issuance, and thus improving the safety of the operational process.

[0064] Record each instance where the safety confidence level is less than the confidence threshold and its final manual review result. If the review result in this historical record matches the matching degree determined before review, the data is considered accurate; otherwise, the data is considered inaccurate. The higher the proportion of accurate data, the higher the reliability of the matching degree. That is, the reliability of the matching degree is positively correlated with the ratio of accurate reviews to the total number of reviews. For example, in one embodiment, for cases of physical lag, if the historical record shows that 90 out of 100 instances were indeed due to a spreader malfunction or accurate sensor readings, and only 10 were false alarms from the sensor, then the accuracy rate of this type of conflict reaches 90%, and the data reliability of this type of conflict is very high.

[0065] Furthermore, in some embodiments, a correction factor is determined. m represents the number of accurate warnings, and n represents the total number of warnings. The number of accurate warnings corresponds to the aforementioned number of accurate reviews, and the total number of warnings corresponds to the aforementioned total number of reviews. λ is the learning rate, for example, set to 0.1. In the previous example, H was, for example, 1.04, slightly increasing the safety confidence level for this type of conflict.

[0066] In some embodiments, the correction factor is positively correlated with data confidence. Determining the safety confidence level based on the baseline safety confidence level and the correction factor includes: determining the product of the baseline safety confidence level and the correction factor as the safety confidence level; or, determining the sum of the baseline safety confidence level and the correction factor as the safety confidence level. That is, the higher the data reliability, the higher the correction factor. This directly links data confidence level with safety confidence level, enabling dynamic responses to data quality in safety decisions. When data confidence is high, the correction factor increases accordingly. The effectiveness of the baseline safety confidence level can be strengthened through product or summation calculations, making the safety decision results more consistent with actual operational situations. When data confidence is low, the correction factor decreases accordingly, weakening the weight of the baseline safety confidence level and avoiding risky decisions based on low-quality data. This helps to further improve the accuracy of safety confidence level calculation, thereby ensuring the rationality of instruction issuance and ultimately improving the safety of the operational process.

[0067] In some embodiments, the operating environment includes external environmental risk data and / or internal device health data. Determining a correction factor based on the current operating environment includes: determining the correction factor based on the external environmental risk data and / or internal device health data. This incorporates objective environmental factors of the operating scenario, making the safety confidence calculation process more compatible with the actual environment and equipment operating conditions. It avoids using fixed judgment criteria in special circumstances such as high-risk environments or poor equipment condition, making safety judgments more adaptable and contributing to further improvements in the safety of the operating process.

[0068] In some embodiments, the correction factor is negatively correlated with the severity of external environmental risks represented by external environmental risk data; and positively correlated with the health status represented by internal device health data. The safety confidence level is determined based on the baseline safety confidence level and the correction factor, including: determining the product of the baseline safety confidence level and the correction factor as the safety confidence level; or, determining the sum of the baseline safety confidence level and the correction factor as the safety confidence level. Higher external environmental risks result in a smaller correction factor, which, through calculation, lowers the safety confidence level, allowing for a more cautious assessment of operational safety and the early initiation of protective measures. Higher internal device health results in a larger correction factor, correspondingly increasing the safety confidence level and facilitating the workflow. This allows the safety confidence level to respond in real-time to changes in environmental risks and equipment status, ensuring that the instruction issuance process balances safety and flexibility, further strengthening the safety assurance of the operational process.

[0069] For external environmental risk data, the correction factor is set to a smaller value, for example, 0.9, in high-risk operating environments such as nighttime, rain, fog, and peak hours. For internal device health data, if the sensor self-test signal-to-noise ratio reported by the vehicle end has a low signal-to-noise ratio or a recent history of brief malfunctions, its weight is reduced from 1.0 to 0.8.

[0070] In some embodiments, determining a correction factor based on external environmental risk data and / or internal device health data includes: determining the correction factor. S is determined based on the health data of internal components, while R is determined based on the risk data of the external environment.

[0071] In some embodiments, a correction factor is determined based on the matching degree of historical time points and the current operating environment, including: determining a first correction factor based on the matching degree of historical time points and determining a second correction factor based on the current operating environment. A safety confidence level is determined based on a baseline safety confidence level and the correction factor, including: jointly determining the safety confidence level based on the baseline safety confidence level, the first correction factor, and the second correction factor. By determining the first correction factor based on historical matching degree and the second correction factor based on the current operating environment, and then combining both with the baseline safety confidence level to calculate the safety confidence level, the reliable experience of historical operating data is referenced, while also adapting to the real-time environment and equipment operating conditions. This ensures that safety judgments possess both stability and scenario adaptability, further improving the accuracy of the safety confidence level.

[0072] The process of determining the first correction factor based on the matching degree of historical moments is executed in the same manner as described above, and will not be repeated here. Similarly, the process of determining the second correction factor based on the current work environment is executed in the same manner as described above, and will not be repeated here.

[0073] That is, determine the security confidence level. Where M is the baseline security confidence level, W1 is the first correction factor, and W2 is the second correction factor.

[0074] In some embodiments, issuing non-operational instructions to the work vehicle includes: identifying a target non-operational instruction corresponding to a safety confidence level among multiple levels of non-operational instructions, and issuing the target non-operational instruction. This achieves hierarchical control, executing different response strategies for different safety scenarios. The safety confidence level directly reflects the level of operational risk, and matching it to different levels of non-operational instructions allows for appropriate early warnings when the risk is low, avoiding over-protection that could affect operational efficiency; and for strong protective measures when the risk is high, ensuring safety. This refined hierarchical control achieves both precise risk control and efficient workflow, making safety protection more targeted and reasonable, and comprehensively improving the safety of the work process and overall operational efficiency.

[0075] Non-operational instructions include at least one of the following: alarm instructions, prohibition instructions indicating that the work vehicle is prohibited from performing operations, and preset protective instructions. Specifically, issuing an alarm instruction to the work vehicle includes: determining a target alarm instruction corresponding to the current safety confidence level among multiple levels of alarm instructions, and issuing the target alarm instruction to the work vehicle. Issuing a protective instruction to the work vehicle includes: determining a target protective instruction corresponding to the current safety confidence level among multiple levels of protective instructions, and issuing the target protective instruction to the work vehicle. In some embodiments, issuing a non-operational instruction to the work vehicle includes: issuing an alarm instruction to the work vehicle when the safety confidence level is high; and issuing a protective instruction to the work vehicle when the safety confidence level is low.

[0076] The implementation method will be further explained below with reference to Table 1.

[0077] Table 1: Main risk scenario 1: Protection against dragging risks.

[0078] In real-world applications, if the spreader or forklift forks are not completely separated from the container, unmanned truck movement can cause mechanical damage and create a risk of being dragged.

[0079] The machine-side coordination unit, such as a gantry crane, uploads its official operational status to the ECS interface reported to the field control center. The vehicle-side execution unit reports the physical perception data identified by visual and lidar sensors to the ECS interface of the field control unit. The ECS simultaneously pushes the data to the risk fusion decision-maker. The risk fusion decision-maker performs a dual-source consistency check. For example, the operational status is denoted as logical value L, and the physical perception data as P. When the operational status is "release complete" and the physical perception data indicates separation has been detected, the risk fusion decision-maker determines a high safety confidence level and triggers subsequent operational instructions. If there is an information conflict, such as an operational status of "release complete" but physical perception data indicating no effective separation has been detected, the safety confidence level is significantly reduced, triggering protection.

[0080] Level 1 protection is set to command-level blocking. If the risk fusion decision-maker does not receive the work status or the verification fails, it will not generate a departure permit for that work, preventing risks at the source. Level 2 protection is set to vehicle-side arbitration intervention. If the decision-maker issues a departure permit, the onboard safety controller performs a final local verification before execution. If the local sensors still detect a physical connection, the onboard safety controller refuses to execute the permit and issues an alarm, achieving active protection. Level 3 protection is set to physical-level braking. While the work vehicle is moving, the onboard safety controller continuously monitors. If it detects an unexpected tendency for movement to be carried away, it immediately triggers emergency braking, requiring manual intervention.

[0081] In the scenario of preventing towing risks, if the operation status is "Grab Start," it means the desired physical state is that the spreader and container are in contact or locked. If the physical sensing data indicates that the actual physical state is a tight contact, the matching degree is consistent, and the safety confidence level is set to 1.0. Subsequent operation instructions allow the truck to wait at a safe distance. If the physical sensing data indicates that the actual physical state is a significant separation gap, the matching degree is conflicting, denoted as Type I. The safety confidence level is set to 0.5. A warning is subsequently issued to check the spreader's movement or sensors, keeping the truck waiting. If the operation status is "Release Complete," it means the desired physical state is that the spreader and container are physically separated. If the physical sensing data indicates that the actual physical state is a separation gap that meets the standard, the matching degree is highly consistent, and the safety confidence level is set to 1.2, which is one of the core conditions for generating a safe passage permit. If the physical sensing data indicates that no effective separation is detected, the matching degree is severely conflicting, denoted as Type II, and the safety confidence level is significantly reduced to 0.3. At this point, secondary protection is triggered, prohibiting the vehicle safety controller (VSCU) from executing driving commands and reporting a "separation unconfirmed" alarm. If the operating status is ECS (Equipment Control System) command loss or timeout, the actual physical status is any, the safety confidence level is set to 0.5, a conservative strategy is triggered, assuming it is unsafe, maintaining the current safe status or requiring manual confirmation.

[0082] Main risk scenario two: Risk protection for suspended box passage.

[0083] In real-world applications, there are suspended containers beneath the lifting machinery, posing a threat to passage and creating a risk of suspended container passage.

[0084] The risk fusion decision-maker integrates the crane's real-time location and "working" status from the ECS interface with point cloud data of suspended obstacles from the roadside unit and the vehicle-mounted top radar, thus forming the physical perception data. Based on the fusion results, the risk fusion decision-maker calculates the precise projection area of ​​the suspension box in real time. The decision-maker dynamically generates and broadcasts a dynamic electronic fence instruction covering this projection area to all relevant working vehicles.

[0085] Simultaneously, restriction commands can be issued to work vehicles about to enter the area. After receiving the restriction command, the on-board safety controller of each work vehicle immediately replans the route to bypass the electronic fence and controls the vehicle to pass through the adjacent area at a limited speed.

[0086] The method further includes determining the projection area based on the location of the suspended box, and determining a temporary restricted area based on the projection area and height. The temporary restricted area forms an electronic fence. The temporary restricted area must at least cover the entire current projection area of ​​the suspended box. Using the projection area as a reference, the edge of the temporary restricted area expands outward as the height of the suspended box increases, and the area of ​​the temporary restricted area is positively correlated with the height of the suspended box.

[0087] In the scenario of suspended obstacle passage risk protection, if the crane is in operation and has location information, it indicates that there is a suspended obstacle in the air above a specific area. If the physical sensing data indicates that the roadside or roof radar has detected a suspended target, the matching degree is consistent, and the safety confidence level is 1. The risk fusion decision-maker generates a dynamic restricted zone. If the physical sensing data indicates that no target was detected in the sensing area, it indicates that the matching degree of the two is not conflicting, and the type is type III indicating missed detection. At this time, the safety confidence level is 0.4. Based on the logical state, the potential risk area is still marked, and the sensing system is checked. If the crane is idle or moved, it indicates that there is no suspended obstacle above the area. If the physical sensing data indicates that there is no target, the matching degree of the two is consistent, and the safety confidence level is 1. The dynamic restricted zone is lifted or reduced. If the physical sensing data indicates that a suspended target was still detected, the matching degree of the two is conflicting, recorded as type IV indicating residual false alarm. At this time, the safety confidence level is 0.6. A warning or review is performed. If it is a sensor false alarm or a foreign object, the restriction is temporarily lifted.

[0088] Main risk scenario three: Security protection against website lockout interactions.

[0089] In real-world applications, the area around the lock station is often a mix of human and machine users and vehicle-to-machine devices, which can easily lead to collisions and pose a risk to safe interaction at the lock station.

[0090] The work instruction system and the risk fusion decision-maker work together to ensure that only one truck is dispatched at a time to the same lock station, and generate a work instruction indicating that the lock station is ready. The risk fusion decision-maker integrates monitoring data on personnel and equipment from fixed sensing devices around the lock station, such as cameras and LiDAR. The risk fusion decision-maker only issues a unique entry permit to the target work vehicle when both the work instruction and environmental monitoring are safe. Based on this permit, the onboard safety controller of the work vehicle controls the vehicle to enter in a creeping mode. After entering, the onboard safety controller relies on local surround-view perception for real-time monitoring, and any abnormality will immediately trigger a stop.

[0091] In the scenario of safety interaction risk protection at the station lock, if the operation status is "station lock ready" and truck A enters, it means that truck A should be inside the station, and its movement status is correct. If the physical perception data indicates that the visual recognition is truck A, and it enters at low speed, then the matching degree between the two is consistent, the safety confidence level is 1, and truck A is allowed to crawl into the station. If the physical perception data indicates that the recognition is truck B or other objects, then the matching degree between the two is a serious conflict, recorded as type V indicating an incorrect object, and the safety confidence level is 0.2. This triggers an interactive sequence control interruption, prohibits entry into the station, and reports a vehicle identity error. If the physical perception data indicates that personnel have been detected entering, then the matching degree between the two is a serious conflict, recorded as type VI indicating an incorrect object, and the safety confidence level is 0.1. An emergency stop command is immediately sent to the truck, and a full-site alarm is broadcast.

[0092] Main risk scenario four: Failure risk protection in critical areas. Commonly seen at the edge of docks.

[0093] In real-world applications, vehicles may veer into dangerous areas due to malfunctions or signal loss, posing a risk of failure in critical areas. For example, a vehicle may veer towards the edge of a dock due to control failure or signal loss, posing a risk of falling into the sea.

[0094] The vehicle-mounted safety controller continuously compares high-precision positioning data with preset static electronic geofences and analyzes vehicle trajectory deviations. Specifically, it combines GNSS (Global Navigation Satellite System) and IMU (Inertial Measurement Unit) to monitor the relative position of the vehicle and the electronic geofence in real time. It compares the predetermined path with the actual trajectory to detect uninstructed deviations. The vehicle-mounted safety controller also monitors the communication link status with the field station.

[0095] Level 1 protection is set to yaw warning. When the trajectory deviation exceeds a threshold, it indicates that the work vehicle's trajectory has slightly deviated. The onboard safety controller makes a local decision, triggering an audible and visual alarm and slowing down. Level 2 protection is set to remote takeover. When the vehicle is severely out of control and communication is normal, the onboard safety controller reports the status, and the field control center issues a forced deceleration command. Level 3 protection is set to vehicle self-rescue. When communication is interrupted and the vehicle is about to cross the safety boundary, the onboard safety controller, based on the last known safety command and local perception, autonomously decides to trigger maximum braking and stop the vehicle, achieving ultimate safety redundancy.

[0096] Under normal operating conditions, if the operation is in normal parallel traffic, the ideal state is an unobstructed path. If the physical sensing data indicates that the sensor detects no obstacles on the path, the matching degree between the two is consistent, and the safety confidence level is 1, allowing the vehicle to proceed at the prescribed speed. If the physical sensing data indicates that a static obstacle is detected, the matching degree between the two is conflicting, denoted as Type VII representing environmental change. The safety confidence level is 0.5, triggering a yaw warning and local path replanning. If the yaw cannot be corrected within a certain time, the vehicle loses control, triggering remote takeover and forced speed reduction. If the physical sensing data indicates that a suddenly appearing dynamic target is detected, the matching degree between the two is conflicting, denoted as Type VIII representing a dynamic threat. The safety confidence level is 0.53, triggering Level 3 protection and initiating the emergency braking plan.

[0097] In some embodiments, the method further includes: determining the work instruction to be executed based on the operating status of the working equipment. That is, determining further work instructions based on the current operating status, which helps to ensure continuous and consistent execution of the work.

[0098] This application provides an electronic device including one or more processors for performing the aforementioned method for controlling a work vehicle. Specifically, the electronic device includes a field control unit.

[0099] Combination Figure 5 As shown, this application embodiment provides a method for controlling a work vehicle, including steps S21 to S23.

[0100] Step S21: Receive field-end commands from the field-end control unit; field-end commands include work commands or non-work commands. The work commands and non-work commands here are generated by executing the aforementioned method.

[0101] Step S22: Perform real-time verification on the local sensor to obtain the local verification result.

[0102] Before executing field-side commands, local sensors are calibrated in real time to obtain local calibration results. The main sensor is the sensor in the vehicle-mounted fusion perception system of the vehicle-side execution unit.

[0103] Step S23: Determine whether the local verification result is consistent with the operational intent of the field-end command, so as to determine whether to execute the field-end command.

[0104] In this way, the coordination of the work process is ensured through global decision-making by the field control system, followed by secondary verification to avoid malfunctions caused by field data deviations or command transmission errors. For example, if the field control system instructs the vehicle to move, but the local sensors detect obstacles in the path that have not been identified by the field control system, the instruction can be terminated in a timely manner. This dual safety control further enhances the safety of the work process.

[0105] This application provides an electronic device including one or more processors for executing the method for controlling a work vehicle. Specifically, the electronic device includes a vehicle-side execution unit.

[0106] Specifically, determining whether the local verification result matches the operational intent of the field-end command in order to decide whether to execute the field-end command includes: [determining whether the local verification result matches the operational intent of the field-end command]. Figure 1 When the local verification result is inconsistent with the operational intent of the field command, the control vehicle shall execute the field command; when the local verification result is inconsistent with the operational intent of the field command, the control vehicle shall not execute the field command.

[0107] The vehicle-mounted safety controller ultimately implements an arbitration mechanism. Specifically, the field control unit determines the field command, which may be an operational or non-operational command depending on the actual situation. After the field control unit determines the field command, the vehicle-mounted execution unit does not execute it directly, but instead initiates a local final arbitration mechanism. Specifically, after executing any command for controlling movement, the vehicle-mounted safety controller calls local sensors for a final real-time verification. This verification process is typically on the order of milliseconds. Only when the local verification result matches the safety intent of the field command... Figure 1 When this occurs, the field safety controller further sends the field command to the drive-by-wire chassis for execution. If the local verification result is inconsistent with the safety intent of the field command, the verification fails. For example, if the field command indicates that the vehicle is allowed to leave, but no physical connection is detected locally, the vehicle safety controller will refuse to execute the operation command and issue an alarm, thus achieving active protection at the vehicle end.

[0108] In some embodiments, the method further includes: controlling the work vehicle to enter a safe parking state when communication is interrupted, in order to achieve self-rescue. Specifically, controlling the work vehicle to enter the safe parking state includes: entering the safe parking state based on the last valid command and body perception, thereby ensuring safety through a failure mechanism.

[0109] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, performs the aforementioned method for controlling a work vehicle.

[0110] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are quite specific and detailed. However, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the inventive concept of this application, and these modifications and improvements all fall within the protection scope of this application.

[0111] In the description of this application, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first," "second," etc., may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

Claims

1. A method for controlling a work vehicle, characterized in that, include: During the operation of the working equipment, the current operating status of the working equipment is obtained; Obtain physical sensing data associated with the operation process; The safety confidence level is determined based on the degree of matching between the operation status and the physical sensing data; When the safety confidence level is greater than or equal to the confidence threshold, a work instruction is issued to the work vehicle, the work instruction being used to control the work vehicle to operate; If the safety confidence level is less than the confidence level threshold, a non-operation instruction is issued to the work vehicle; the non-operation instruction is used for early warning and / or protection of the work vehicle.

2. The method according to claim 1, characterized in that, The step of determining the safety confidence level based on the degree of matching between the operation status and the physical sensing data includes: A baseline safety confidence level is determined based on the degree of matching between the operational status and the physical sensing data; The correction factor is determined based on the degree of matching at historical moments and / or the operating environment of the current operation. The security confidence level is determined based on the baseline security confidence level and the correction factor.

3. The method according to claim 2, characterized in that, The correction factor is determined based on the degree of matching at historical moments, including: The data reliability of the matching degree is determined based on the matching degree at multiple historical moments and the verification results of the matching degree at the multiple historical moments. The correction factor is determined based on the reliability of the data.

4. The method according to claim 3, characterized in that, The correction factor is positively correlated with the data reliability. Determining the security confidence level based on the baseline security confidence level and the correction factor includes: The product of the baseline security confidence level and the correction factor is determined as the security confidence level; or The sum of the baseline security confidence level and the correction factor is determined as the security confidence level.

5. The method according to claim 2, characterized in that, The operating environment includes external environmental risk data and / or internal device health data; Based on the current work environment, determine the correction factors, including: The correction factor is determined based on external environmental risk data and / or internal component health data.

6. The method according to claim 5, characterized in that, The correction factor is negatively correlated with the severity of the external environmental risk represented by the external environmental risk data; the correction factor is positively correlated with the health level represented by the internal device health data. Determining the security confidence level based on the baseline security confidence level and the correction factor includes: The product of the baseline security confidence level and the correction factor is determined as the security confidence level; or The sum of the baseline security confidence level and the correction factor is determined as the security confidence level.

7. The method according to claim 1, characterized in that, The issuance of non-operation instructions to the work vehicle includes: Among the non-operation instructions at multiple levels, a target non-operation instruction corresponding to the value of the safety confidence level is determined, and the target non-operation instruction is issued.

8. A method for controlling a work vehicle, characterized in that, Also includes: Receive field-end instructions issued by the field-end control unit; the field-end instructions include work instructions or non-work instructions, and the work instructions and the non-work instructions are generated by performing the method as described in any one of claims 1 to 7; Perform real-time verification of local sensors to obtain local verification results; Determine whether the local verification result is consistent with the operational intent of the field-end command to decide whether to execute the field-end command.

9. The method according to claim 8, characterized in that, The step of determining whether the local verification result is consistent with the operational intent of the field-end command, in order to determine whether to execute the field-end command, includes: When the local verification result matches the operational intent of the field command, the work vehicle is controlled to execute the field command. When the local verification result is inconsistent with the operational intent of the field command, the work vehicle is controlled not to execute the field command.

10. An electronic device, characterized in that, It includes one or more processors for performing the method for controlling a work vehicle as claimed in any one of claims 1 to 7; or the method for controlling a work vehicle as claimed in any one of claims 8 to 9.

11. A computer-readable storage medium, characterized in that, It stores a program that, when executed by a processor, implements the method for controlling a work vehicle as described in any one of claims 1 to 7, or the method for controlling a work vehicle as described in any one of claims 8 to 9.

12. A system for controlling a work vehicle, characterized in that, include: The machine-side coordination unit is used to report the current operating status of the working equipment during its operation. A vehicle-mounted execution unit is used to report physical sensing data associated with the operation process; the work vehicle includes at least a portion of the vehicle-mounted execution unit. The field control unit is used to determine the safety confidence level based on the degree of matching between the operation status and the physical sensing data; When the safety confidence level is greater than or equal to the confidence level threshold, a work instruction is issued to the vehicle-mounted execution unit to control the work vehicle to execute the work instruction, the work instruction being used to control the work vehicle to perform the work. If the safety confidence level is less than the confidence level threshold, a non-operation command is issued to the vehicle-side execution unit. The non-operation command is used for early warning and / or protection of the working vehicle.