A vehicle-machine intelligent driving safety learning and examination method and system and a storage medium

By adopting a data interaction strategy that prioritizes local access while providing cloud-based backup, and by managing account types, the system addresses the issues of insufficient user awareness and synchronization of examination rights in intelligent driving systems. This approach enables rapid response, improved compliance and safety, and ensures the proper use of intelligent driving functions.

CN122116708APending Publication Date: 2026-05-29CHINA FAW CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA FAW CO LTD
Filing Date
2025-12-12
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

The lack of user awareness, the inability to synchronize test rights data in real time, and the simplistic management strategies for function switch status in existing intelligent driving systems have led to safety hazards and poor user experience.

Method used

It adopts a data interaction strategy that prioritizes local access and provides cloud backup, combining QR code display and proactive polling mechanisms to achieve rapid local response and real-time cloud synchronization. It also manages switch statuses differently based on account type to ensure personalized memory and driving safety.

Benefits of technology

The function enables rapid response activation in offline environments, avoiding repeated testing, improving user experience, ensuring compliance and security of function activation, preventing accidental triggering of intelligent driving functions, and balancing personalized memory with driving safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122116708A_ABST
    Figure CN122116708A_ABST
Patent Text Reader

Abstract

The application discloses a car machine intelligent driving safety learning and examination method and system and a storage medium, relates to the technical field of intelligent networked automobile control, and comprises the following steps: in response to an intelligent driving function starting operation, a cabin domain controller inquires a local examination state corresponding to an account from an intelligent driving domain controller; if the local examination is passed, a starting process is directly executed; if the local examination is not passed, a cloud state is requested, and if the cloud examination is passed, the local storage is synchronously updated and started; if the cloud examination is not passed, an examination two-dimensional code is displayed, and after a real-time result is obtained by using a background polling mechanism, the starting is synchronously performed. The application also relates to a power-off memory strategy based on account classification, and the intelligent driving domain controller performs nonvolatile storage or forced reset of the on-off state according to the account type. The application adopts the logic of local priority and cloud backup and the active polling mechanism, realizes the cross-end non-sensing inheritance of rights and interests, solves the communication bottleneck that the car machine is difficult to receive the push, and ensures the vehicle safety in complex scenes while guaranteeing the personalized experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent connected vehicle control technology, and in particular to a vehicle-machine intelligent driving safety learning and examination method, system and storage medium. Background Technology

[0002] With the evolution of automotive electronic and electrical architecture and the maturity of artificial intelligence algorithms, Advanced Driver Assistance Systems (ADAS) and advanced intelligent driving functions have gradually become standard features in modern cars. While these functions greatly alleviate driver fatigue and improve driving safety, their safe operation often relies on specific Operating Design Domains (ODDs), which impose strict limitations on weather, road conditions, vehicle speed, and the driver's ability to take over. However, in current practical applications, most drivers lack a clear and accurate understanding of the capabilities of intelligent driving systems, often mistaking assisted driving for fully autonomous driving. This leads to a failure to take over the vehicle in a timely manner in scenarios beyond the system's capabilities, resulting in serious safety accidents.

[0003] To address this cognitive bias, existing technologies typically use disclaimers or electronic user manuals to inform users before activating the function. However, this purely text-based approach suffers from significant passivity and formalism. Users often habitually click "agree" or "skip" without truly reading or understanding the risk warnings, rendering safety education ineffective and failing to fundamentally ensure drivers possess the necessary knowledge to use the function. Therefore, introducing a mandatory knowledge assessment mechanism has become an industry trend. However, how to build a rigorous yet convenient examination process on the vehicle's head unit, where computing power and interaction methods are limited, remains a pressing technical challenge.

[0004] Performing complex question-and-answer interactions directly on the vehicle's infotainment screen is not only inefficient but can also consume vehicle resources for extended periods. Using mobile devices (phones) for cross-platform testing presents the challenge of synchronizing data between the device and the cloud. Current in-vehicle communication terminals typically interact with the cloud based on a standard HTTP request-response model, and most in-vehicle systems lack the efficient long-term connection or instant push notification capabilities of mobile internet apps. This means that after a user completes the exam on their mobile device, the cloud server struggles to proactively and in real-time trigger status updates on the vehicle's screen, often resulting in the user having passed the exam but the vehicle still displaying as locked, severely impacting user experience and the continuity of function activation.

[0005] Furthermore, the on / off state management strategies of existing intelligent driving systems are rather rudimentary, typically only configured as power-off memory or power-off reset. If a power-off memory strategy is used, when the owner activates the function and hands the vehicle over to a valet or lends it to someone else, the next driver may unknowingly trigger the active intelligent driving function, creating a potential safety hazard. If a power-off reset strategy is used, the owner must reactivate the function every time they get in the car, which is cumbersome. Existing solutions lack an underlying data management mechanism capable of differentiated configuration based on user identity and usage scenario, failing to ensure both personalized experience and vehicle safety in complex scenarios. Summary of the Invention

[0006] The purpose of this invention is to provide a vehicle-mounted intelligent driving safety learning and examination method, system, and storage medium, which at least solves the technical problems in the prior art where the intelligent driving function activation mechanism relies solely on passive disclaimers and lacks mandatory knowledge assessment, leading to insufficient user awareness, and where the examination rights data cannot be synchronized in real time and seamlessly due to limited communication between the vehicle and the terminal in cross-terminal examination scenarios. It also solves one of the technical problems in the existing intelligent driving function switch status management strategy, which is too simplistic and cannot take into account both personalized memory and driving safety in different usage scenarios based on user identity (such as owner and valet mode).

[0007] The present invention provides the following solution: The first aspect of the present invention provides a vehicle-mounted intelligent driving safety learning and examination method, which is mainly executed collaboratively by a cockpit domain controller, an intelligent driving domain controller and a cloud server.

[0008] In the main process of the method, the system adopts a data interaction strategy of "local priority, cloud backup". Specifically, in response to the activation operation of the intelligent driving function on the cockpit domain controller, the cockpit domain controller first obtains the account information of the currently logged-in user and sends the account information to the intelligent driving domain controller simultaneously. After receiving the account information, the intelligent driving domain controller queries its locally stored data to get feedback on the local test status. The cockpit domain controller performs a hierarchical decision based on this feedback: if the local test status is passed, the function activation process is directly executed, thereby ensuring rapid response of the function in the absence of network or weak network environment; if the local test status is failed, the system further requests the cloud test status from the cloud server.

[0009] When cloud-based interaction is involved, if the cloud-based exam status is "passed," the cockpit domain controller synchronizes this status to the intelligent driving domain controller for local storage updates and then executes the function activation process, achieving seamless cross-device inheritance of user rights. If the cloud-based exam status is still "failed," the cockpit domain controller controls the display interface to output the exam QR code, guiding the user to complete the learning and exam.

[0010] To address the technical challenge of maintaining a persistent connection on the vehicle-mounted system to passively receive cloud push notifications, this method introduces an active polling mechanism during the QR code display phase. After displaying the exam QR code, the cockpit domain controller sends polling requests to the cloud server at a preset period to obtain the real-time cloud exam status. Once a passing status is detected, the cockpit domain controller automatically closes the QR code, sends a synchronization signal containing the exam pass result to the intelligent driving domain controller, and executes the function activation process after receiving confirmation from the intelligent driving domain controller that local storage has been updated. Furthermore, this polling mechanism is equipped with timeout circuit breaking and error message logic. If no status is obtained within a preset time or network access fails, a network error message is output; if a user manually closes the QR code, polling immediately stops to optimize system resource usage.

[0011] At the execution end of the function activation process, this method integrates a compliance check step. The cockpit domain controller sequentially outputs a disclaimer page and a location authorization request pop-up. Only after receiving confirmation of the disclaimer and location permission from the user will the intelligent driving function status be updated to "activated," and a function activation command be issued to the intelligent driving domain controller.

[0012] Furthermore, this method includes a full lifecycle state management mechanism, covering the vehicle power-on initialization and power-off memory processes. During power-on initialization, the cockpit domain controller synchronizes account information to the intelligent driving domain controller. The intelligent driving domain controller queries the locally stored switch memory state and provides feedback, allowing the cockpit domain controller to refresh the displayed state. Simultaneously, the cockpit domain controller verifies cloud data in the background; if inconsistencies are found, a synchronization update is triggered. During the power-off or status query phase, the intelligent driving domain controller executes a differentiated strategy based on account type: for preset normal user accounts, the system reads or saves the switch settings state before the last vehicle power-off, achieving personalized memory; for preset restricted user accounts (such as valet mode accounts or accounts not logged in), the system forcibly resets the switch memory state to the default off state to prevent non-owner users from misusing intelligent driving functions; for preset special permission accounts (such as production line testing or experience mode accounts), the system is configured with bypass check logic, directly allowing the function to be enabled.

[0013] A second aspect of the present invention provides an in-vehicle intelligent driving safety learning and examination system, the system comprising a cockpit domain controller and an intelligent driving domain controller connected via an in-vehicle communication network, and a cloud server connected to the cockpit domain controller via a wireless network.

[0014] The cockpit domain controller incorporates an interactive arbitration module, which serves as the system's logical hub. This module responds to the user's activation of the intelligent driving function, retrieves the currently logged-in account, and initiates a local status query to the intelligent driving domain controller. Based on the results from the intelligent driving domain controller, this module executes logical decisions and sends a request to the cloud server if local data is missing or fails. Specifically, if the cloud-based test fails, the interactive arbitration module controls the UI to display the test QR code and initiates a periodic polling query task to the cloud server until a passing result is obtained, triggering data synchronization and the function activation process.

[0015] The intelligent driving domain controller has a built-in local storage management module, which acts as the system's underlying data guardian. It responds to requests from the cockpit domain controller, performing read and write operations on the local non-volatile memory to query or update the exam status and on / off memory status corresponding to the account information. This module also integrates security policy logic, automatically identifying whether the current account is a normal user account or a restricted user account when the vehicle is powered on or off, and accordingly performing either a power-off state retention operation or a forced reset operation to ensure that the functional status matches the current user's permission level.

[0016] The cloud server has a built-in exam data service module, which is configured as the system's data source. It is responsible for maintaining global user exam pass records and, as a passive responder, processes single query requests or high-frequency polling requests from the cockpit domain controller, providing real-time cloud exam status feedback.

[0017] A third aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the vehicle-mounted intelligent driving safety learning and examination method described in the first aspect above.

[0018] The above solution achieves the following beneficial technical effects:

[0019] This application employs a funnel-shaped decision logic that prioritizes local access and uses cloud-based fallback. It prioritizes retrieving the local storage status of the intelligent driving domain controller and combines it with cloud-based status synchronization technology. This ensures that the vehicle can still quickly respond to the activation requests of compliant users even in scenarios without network connectivity. It achieves seamless cross-terminal inheritance of user rights, avoids the tediousness of repeated examinations, and significantly improves the response speed and user experience of function activation.

[0020] This application overcomes the communication bottleneck of traditional vehicle infotainment systems, which struggle to maintain long connections to receive cloud pushes, by constructing an interactive mechanism that combines QR code front-end display with background thread active polling. It utilizes HTTP polling at a preset period to actively retrieve exam results and employs a timeout circuit breaker algorithm. This enables millisecond-level automatic unlocking of vehicle infotainment functions after the user passes the exam on their mobile device, effectively preventing resource consumption caused by network deadlock and ensuring the real-time performance and stability of end-to-cloud interaction.

[0021] This application implements a power-off memory and reset strategy based on account type at the bottom layer of the intelligent driving domain controller. It performs non-volatile storage for the owner's account and forces a power-off reset for restricted accounts. Combined with mandatory location authorization and liability waiver signing process, it fundamentally eliminates the safety hazards caused by accidental triggering of intelligent driving functions in scenarios where the vehicle is lent out or parked in a valet parking environment while preserving the owner's personalized usage habits. This ensures the compliance of the functional operation design domain and effectively balances personalized driving memory and driving safety. Attached Figure Description

[0022] Figure 1 This is an application scenario and system architecture diagram provided by an embodiment of the present invention.

[0023] Figure 2 This is the main flowchart of the intelligent driving function activation decision provided in the embodiment of the present invention.

[0024] Figure 3 This is a timing diagram of the interaction between QR code examination and cloud polling provided in an embodiment of the present invention.

[0025] Figure 4 This is a system functional module block diagram provided in an embodiment of the present invention.

[0026] Figure 5 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0027] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0028] See attached document Figure 1This invention provides an in-vehicle intelligent driving safety learning and testing system, applicable to vehicles equipped with intelligent driving functions. The system includes: a Cockpit Domain Controller (CSC), a High Automated Driving Domain Controller (HAD), a cloud server, and a mobile terminal.

[0029] The cockpit domain controller and the intelligent driving domain controller establish a communication connection via an in-vehicle communication bus. This in-vehicle communication bus utilizes CAN (Controller Area Network) or in-vehicle Ethernet technology to achieve bidirectional real-time data transmission. The cockpit domain controller establishes a wireless communication connection with the cloud server via an in-vehicle wireless communication module (e.g., T-BOX), using 4G, 5G, or Wi-Fi networks for data interaction. Mobile terminals communicate with the cloud server via the mobile internet.

[0030] The cockpit domain controller, serving as the hub for human-machine interaction and data communication, is equipped with a display screen and touch interface. It provides a graphical user interface, displaying intelligent driving function switches, exam QR codes, disclaimers, and location authorization pop-ups. Simultaneously, the cockpit domain controller manages the current vehicle's login account information and synchronizes this information to the intelligent driving domain controller. Furthermore, it is configured to initiate data requests to the cloud server to retrieve exam results and synchronize the latest exam pass status to the intelligent driving domain controller.

[0031] The Intelligent Driving Domain Controller, serving as the execution unit for intelligent driving functions and the local data storage center, is internally equipped with non-volatile memory (such as Flash or EEPROM). The Intelligent Driving Domain Controller receives account information and exam pass status from the Cockpit Domain Controller, and stores the on / off status of the intelligent driving function and the exam pass result in the associated non-volatile memory. Based on the received instructions and the locally stored data, the Intelligent Driving Domain Controller comprehensively determines whether to activate the intelligent driving function and feeds back the current on / off status and local exam status to the Cockpit Domain Controller.

[0032] The cloud server is configured with a database to store the intelligent driving learning and examination records corresponding to each user account. The cloud server responds to query requests from the cockpit domain controller and provides feedback on the latest cloud-based examination status. Simultaneously, the cloud server provides an online examination service interface to mobile terminals and updates examination results in real time.

[0033] In this embodiment, the vehicle's ignition state is defined as having a power-on state (IG ON) and a power-off state (IG OFF). IG ON indicates that the ignition switch is on and the vehicle's core circuitry is activated; IG OFF indicates that the ignition switch is off and the vehicle's main functions are powered down. The intelligent driving domain controller is configured to retain data in its non-volatile memory during the IG OFF state so that historical states can be read the next time IG ON occurs.

[0034] In this embodiment, the system manages permissions based on user account (UserID) and account type (AccountType). The signals synchronized between the cockpit domain controller and the intelligent driving domain controller include the local user ID signal (LocalUserID) and the account type signal (AccountType). The system supports a preset number of user account slots, such as 10 account slots.

[0035] Specifically, the logic for defining user accounts is as follows:

[0036] Accounts with an ID of 0 (ID=0) are defined as special or default accounts, including default accounts, agency mode accounts, production line accounts, and trial accounts.

[0037] Accounts with IDs from 1 to 9 (ID=1-9) are defined as normal user accounts.

[0038] Regarding account type (AccountType), the system is configured with the following processing logic:

[0039] When AccountType indicates production line account (Type=0x03), the system is configured to allow the intelligent driving function switch to be turned on directly without scanning the code for learning.

[0040] When AccountType indicates a trial account (Type=0x04), the system is configured to allow the intelligent driving function switch to be turned on directly without scanning a code for learning.

[0041] When the account ID is 0 and the AccountType is not equal to 0x03 or 0x04 (corresponding to the default account without an account or valet mode account), the system is configured not to support QR code learning, forcibly disables the intelligent driving function switch, and does not save the memory of the switch state.

[0042] For normal user accounts (ID=1-9), the system is configured to support the QR code learning process and has a state memory function. That is, when the vehicle enters the IG ON state again after IG OFF and sleep, the intelligent driving domain controller reads the previous on / off state corresponding to the account ID from the local memory and maintains that setting state.

[0043] The feedback signals sent by the intelligent driving domain controller to the cockpit domain controller include switch status signals and test result signals (e.g., signal ADL29_NotifyHPA_Studyprompt_uint8_JO). The cockpit domain controller updates the switch display status (ON or OFF) on the display screen based on these feedback signals. If the cockpit domain controller does not receive a feedback signal from the intelligent driving domain controller within a preset time threshold (e.g., 2 seconds), or if the signal times out, the cockpit domain controller switches the display status to the default off state (OFF).

[0044] The method provided by this invention performs strict data synchronization and state recovery logic during the vehicle startup phase to ensure consistent user experience and driving safety.

[0045] See attached document Figure 2 When the vehicle ignition switch is in the IG ON position, the cockpit domain controller starts and completes the user account login process. The cockpit domain controller obtains the currently logged-in user's account ID (UserID) through its internal user management module and synchronously sends this account ID to the intelligent driving domain controller via the vehicle's Ethernet or CAN bus. At this time, the intelligent driving domain controller is in standby mode, ready to receive the synchronization signal sent by the cockpit domain controller.

[0046] Upon receiving the account ID, the intelligent driving domain controller immediately executes a local storage query. The controller accesses its internal non-volatile memory and retrieves the corresponding historical data record based on the received account ID. The historical data record includes the intelligent driving function switch status (SwitchStatus_Last) and the local exam pass status (ExamStatus_Local) saved for that account at the last time the vehicle was IG OFF (power off).

[0047] During the retrieval process, the intelligent driving domain controller categorizes account IDs according to a preset account permission policy. When an account ID is identified as belonging to a normal user account (e.g., IDs 1 to 9), the intelligent driving domain controller reads the corresponding SwitchStatus_Last. If the read SwitchStatus_Last is ON, the intelligent driving domain controller sets the execution status of the current function to ON; if it is OFF, it sets it to OFF. This mechanism ensures that after a normal user parks for a short time or starts the vehicle overnight, the on / off state of the intelligent driving function can automatically return to the previous usage state without requiring the user to repeat the operation.

[0048] When the intelligent driving domain controller recognizes that the account ID belongs to a restricted user account (e.g., ID 0, corresponding to valet mode, temporary visitor, or not logged in), the intelligent driving domain controller executes a forced reset logic. Regardless of the account's previous history, the intelligent driving domain controller forcibly sets the execution status of the current function to OFF, and does not record any on / off status changes for this account in the current driving cycle. This logic is used to prevent valet parking personnel or non-owner users from accidentally activating intelligent driving functions without authorization.

[0049] The intelligent driving domain controller packages the determined current on / off state and local test pass status into a feedback signal and sends it back to the cockpit domain controller via the communication bus. The cockpit domain controller receives this feedback signal and drives the intelligent driving function on / off UI component on the display screen according to the feedback content. If the feedback signal indicates ON, the UI component is highlighted or in an on state; if the feedback signal indicates OFF, the UI component is grayed out or in a off state. Before receiving the feedback signal, the cockpit domain controller displays the on / off state as loading or default off to avoid state jumps.

[0050] Meanwhile, during the background process of vehicle power-on initialization, the cockpit domain controller executes a silent data synchronization procedure with the cloud. After confirming a normal in-vehicle wireless network connection, the cockpit domain controller sends an exam status query request for the current account ID to the cloud server. This step runs in the background and does not block the display of the foreground UI.

[0051] The cloud server responds to the query request, providing the latest cloud exam status (ExamStatus_Cloud) recorded for the account ID in the cloud database. Upon receiving ExamStatus_Cloud, the cockpit domain controller compares it with ExamStatus_Local obtained from the intelligent driving domain controller.

[0052] If the comparison results are inconsistent—specifically, ExamStatus_Cloud indicates "passed" while ExamStatus_Local indicates "failed" or "no record"—the cockpit domain controller generates a status update command and synchronously sends ExamStatus_Cloud to the intelligent driving domain controller. The intelligent driving domain controller responds to this update command, updating the exam status corresponding to that account ID in its local non-volatile memory to "passed." Through this silent synchronization mechanism, once a user completes the exam on a mobile terminal or in another vehicle and synchronizes it to the cloud, this vehicle automatically synchronizes the latest exam pass status without requiring the user to scan the code again.

[0053] After the vehicle is powered on and initialized, the user can activate the intelligent driving function (such as Highway Navigation Assist (NOA) or Memory Parking (HPA)) via the cockpit domain controller's touchscreen display. In response to this touch event, the cockpit domain controller first locks the context of the current operating interface and then calls the account management service interface to obtain the currently logged-in user's account ID (UserID).

[0054] After obtaining the account ID, the cockpit domain controller does not directly send a request to the cloud, but instead prioritizes executing local authentication logic. The cockpit domain controller sends a local status query message containing the function request type and account ID to the intelligent driving domain controller via the vehicle Ethernet. The intelligent driving domain controller parses this message and uses the received account ID as the index key to retrieve the corresponding local exam status value (ExamStatus_Local) from a database or lookup table built in local non-volatile memory.

[0055] The intelligent driving domain controller sends the retrieved ExamStatus_Local value back to the cockpit domain controller. If the ExamStatus_Local value is valid (e.g., the flag is 0x01), the cockpit domain controller determines that local authentication is successful. At this point, regardless of the network signal strength of the in-vehicle wireless communication module (T-BOX), or even in the absence of a network connection, the cockpit domain controller recognizes that the account is qualified to enable the function. Subsequently, the cockpit domain controller enters the pre-activation check process, including calling the positioning module interface to query whether the current vehicle is within the approved geofence range, and calling the disclaimer module to determine whether the user has signed the relevant agreement. Once the positioning authorization and disclaimer signing are confirmed to be correct, the cockpit domain controller renders the switch control on the interface as enabled and sends a function activation command (Function_Active_Cmd) to the intelligent driving domain controller.

[0056] If the ExamStatus_Local value returned by the intelligent driving domain controller is "not passed" (e.g., the flag is 0x00) or "no record" (Null), the cockpit domain controller determines that local authentication has failed, thus triggering the cloud-based fallback logic. The cockpit domain controller checks the current network connection status. If the network connection is normal, it sends a cloud-based exam status query request for the account ID to the cloud server via an HTTPS encrypted channel.

[0057] The cloud server queries the backend database and returns the query result (ExamStatus_Cloud) to the cockpit domain controller. If the value of ExamStatus_Cloud is "pass," it indicates that the user has already completed the safety learning exam on another terminal or previously, but the data has not yet been synchronized to the vehicle's local storage. At this time, the cockpit domain controller performs a dual operation of data synchronization and function activation: on the one hand, the cockpit domain controller generates a write command, packages the account ID and pass status, and sends it to the intelligent driving domain controller. Upon receiving the command, the intelligent driving domain controller immediately updates its local non-volatile memory to ensure that the local storage status is "pass" for the next query; on the other hand, after confirming that the data synchronization command has been successfully sent, the cockpit domain controller immediately jumps to execute the aforementioned pre-activation check process (location and disclaimer), and activates the function after the check is passed. This mechanism ensures that the user's rights are seamlessly inherited after changing vehicles or resetting the vehicle's infotainment system.

[0058] See attached document Figure 3 If the ExamStatus_Cloud value returned by the cloud server is "Not Passed," or if the cockpit domain controller encounters a network unreachable exception when requesting the cloud, the cockpit domain controller determines that the account is not currently qualified to activate the function. In this case, the cockpit domain controller blocks the sending of the function activation command, keeps the switch control in the off state, and triggers the online examination interaction process. The cockpit domain controller calls the rendering engine to generate and pop up a QR code floating window or full-screen page containing a specific URL link on the current display interface, guiding the user to scan the code using their mobile device to enter the online learning and examination interface.

[0059] When the cockpit domain controller confirms that both the local and cloud-based exam results are failed, it invokes the graphics rendering engine to generate a modal dialog box on top of the current display. The core area of ​​this dialog box displays a QR code (Quick Response Code) containing exam link information, along with a prompt to scan the code with your phone to complete the safety learning exam and a cancel control to close the dialog box. At this time, the cockpit domain controller temporarily suspends the activation request for the intelligent driving function, keeping the function switch off and blocking all UI operations except closing the dialog box.

[0060] While displaying the QR code, the cockpit domain controller starts a separate background polling thread. This polling thread is configured to send Hypertext Transfer Protocol (HTTP) requests to the cloud server at preset time intervals to actively retrieve the latest exam results. In this embodiment, the preset time interval is set to 2000 milliseconds (i.e., 2 seconds). The query request message constructed by the cockpit domain controller includes the currently logged-in user's account ID and vehicle identification number (VIN). After receiving the request, the cloud server queries the backend database for the real-time exam status field corresponding to the account ID.

[0061] During this period, the user scans the QR code displayed on the cockpit domain controller screen using their mobile device. The mobile device parses the Uniform Resource Locator (URL) in the QR code and redirects the user to an online exam page provided by the cloud server via the mobile network. After the user completes the questions and submits them on the mobile device, the cloud server scores the answers. If the score reaches a preset threshold, the cloud server immediately updates the exam status field corresponding to that account ID in the database from "failed" to "passed".

[0062] When the cockpit domain controller's polling thread sends a query request and receives a response message from the cloud server, it parses the status code in the message. If the parsed status code indicates that the exam status is still "failed," the cockpit domain controller maintains the QR code display and resets the timer to wait for the next polling cycle. When the parsed status code indicates that the exam status has changed to "passed," the cockpit domain controller immediately executes the status synchronization and function unlocking process. Specifically, the cockpit domain controller first terminates the polling thread and stops sending requests to the cloud server to release network resources and processor computing power; subsequently, the cockpit domain controller automatically closes the QR code modal dialog box on the screen and triggers a synchronization action with the intelligent driving domain controller.

[0063] The cockpit domain controller sends a synchronization signal containing a test pass status bit to the intelligent driving domain controller via the vehicle Ethernet. Upon receiving this signal, the intelligent driving domain controller performs a write operation, updating the test status corresponding to the account ID in its local non-volatile memory to "pass," and sends a write success confirmation frame (ACK) to the cockpit domain controller. After receiving the confirmation frame, the cockpit domain controller determines that all prerequisites are met and automatically proceeds to the subsequent function activation process.

[0064] To prevent the polling thread from running indefinitely due to network failures or users abandoning their exams, the cockpit domain controller is equipped with a timeout circuit breaker mechanism. Simultaneously with starting the polling thread, the cockpit domain controller starts a global timer.

[0065] To precisely control the lifecycle of the polling thread, this embodiment uses the following formula to calculate the polling determination criteria:

[0066] ;

[0067] And the circuit breaker is triggered when the following logic is met:

[0068] ;

[0069] in, This indicates the total time consumed by the polling process. Index representing the current polling count; Indicates the first Network round-trip time (RTT) for each HTTP request; This indicates the preset polling interval period (2000ms in this embodiment); This indicates the preset global timeout threshold (e.g., 300,000ms). Indicates the number of polling cycles that have been executed; Indicates the maximum number of retries allowed (e.g., 150 times).

[0070] If the accumulated time of the timer exceeds the preset timeout threshold (e.g., 300 seconds), and the status reported by the cloud does not change to "pass," or if the cockpit domain controller receives HTTP 404 or 500 error codes from the cloud server multiple times consecutively (e.g., 3 times), the cockpit domain controller determines that the interaction has timed out or failed. In this case, the cockpit domain controller forcibly terminates the polling thread and displays a text message (Toast) indicating network connection timeout or abnormal server response on the QR code display interface, prompting the user to check the mobile network or retry.

[0071] Furthermore, if the user clicks the cancel button on the QR code dialog box during the scanning process, the cockpit domain controller responds to this interruption event by immediately destroying the QR code dialog box and simultaneously sending a termination command to the background process, forcibly ending the currently running polling thread. At this time, the intelligent driving function switch remains in the off state, and the system returns to the standby interface, waiting for the user's next activation operation. This interaction mechanism based on active polling and timeout management effectively solves the technical challenge of the vehicle's infotainment system being unable to passively receive cloud push notifications, while ensuring the rational utilization of system resources.

[0072] After the cockpit domain controller confirms that the user's local test status is passed, or after completing the aforementioned cloud polling synchronization process, the system does not immediately activate the intelligent driving function. Instead, it forcibly enters the safety pre-check process. This process aims to ensure that the driver has a full legal understanding of the boundaries of the intelligent driving system and to ensure that the vehicle obtains the necessary geolocation data permissions to support the verification of the Operating Design Domain (ODD).

[0073] The cockpit domain controller first invokes the interface manager to load and render the disclaimer page above the current display layer. The disclaimer page is presented as a full-screen or half-screen modal window, containing a description of the intelligent driving system's capability boundaries, driver takeover responsibility information, and risk warnings for non-autonomous driving functions. At the bottom of this page, the cockpit domain controller has a timer control and a confirmation control. During the initial phase of the page display (e.g., the first 3 seconds), the confirmation control is disabled, forcing the user to read the text; after the countdown ends, the confirmation control automatically switches to an enabled state, allowing the user to click it.

[0074] In response to a user's confirmation action on the disclaimer page (such as clicking the "I have read and agree" button), the cockpit domain controller logs the user's signing behavior and then triggers system-level permission check logic. The cockpit domain controller queries the operating system kernel's permission management service to determine whether the current autonomous driving application has been granted access to high-precision positioning (GNSS) data.

[0075] If unauthorized access is detected, the cockpit domain controller generates a location authorization request command and displays a system-level permission request pop-up, prompting the user that enabling the intelligent driving function requires obtaining the vehicle's location information to match a high-precision map. In response to the user's authorization confirmation action in the location authorization request pop-up (e.g., clicking "Allow"), the cockpit domain controller obtains the location service handle and marks the permission status as authorized. If the user clicks "Deny," the cockpit domain controller terminates the current activation process, automatically closes the disclaimer page, and resets the intelligent driving function switch to the off state.

[0076] After completing the dual confirmation of the aforementioned disclaimer and location authorization, the cockpit domain controller executes the final function activation logic. The cockpit domain controller updates the graphical user interface, rendering the virtual switch controls for the intelligent driving function from a closed state (e.g., a gray slider) to an open state (e.g., a highlighted green slider), accompanied by a feedback prompt indicating that the function is enabled.

[0077] Simultaneously, the cockpit domain controller sends a function activation command to the intelligent driving domain controller via the vehicle communication network. This command is specifically manifested by setting the value of the intelligent driving function enable signal (e.g., the signal name is defined as Func_Pilot_Switch_Req) ​​defined in the communication protocol from 0 (OFF) to 1 (ON).

[0078] Upon receiving the activation command, the intelligent driving domain controller immediately activates its internal perception and planning control algorithm stack and begins monitoring environmental data and high-precision positioning data around the vehicle. At this time, the intelligent driving domain controller is in standby mode. Once the vehicle's driving status meets preset activation conditions (such as vehicle speed, lane line clarity, etc.), the driver can activate the intelligent driving assistance control via steering wheel buttons or levers. By making disclaimers and location authorization mandatory prerequisites, this invention ensures the compliance and safety of function activation.

[0079] To balance convenience and safety in different usage scenarios, this invention constructs a state memory and reset mechanism based on account attributes in the underlying logic of the intelligent driving domain controller. The core of this mechanism lies in implementing differentiated data persistence strategies for different types of user accounts, ensuring that the personalized settings of vehicle owners are retained while preventing temporary user operations from interfering with subsequent use.

[0080] In this embodiment, the intelligent driving domain controller is equipped with non-volatile memory (NVM), such as electrically erasable programmable read-only memory (EEPROM) or flash memory. This memory is used to maintain a mapping table, using the account ID (UserID) as the index key and the intelligent driving function's on / off status (SwitchStatus) and exam pass status (ExamStatus) as associated values.

[0081] In this embodiment, the intelligent driving domain controller is equipped with non-volatile memory (NVM), such as electrically erasable programmable read-only memory (EEPROM) or flash memory. This memory is used to maintain a mapping table, using the account ID (UserID) as the index key and the intelligent driving function's on / off status (SwitchStatus) and exam pass status (ExamStatus) as associated values.

[0082] Specifically, at the physical level of non-volatile memory, the intelligent driving domain controller calculates the starting address of storage corresponding to different account IDs through a linear mapping algorithm. The address calculation formula is as follows:

[0083] ;

[0084] in, This indicates the physical starting address (Hex) of the target account's status data in non-volatile memory; This indicates the base address assigned to the intelligent driving function configuration area (e.g., 0x1000); This represents the account ID value of the currently logged-in user (e.g., 0, 1, 2…9). This indicates the fixed byte length occupied by a single user record (e.g., 4 bytes, including switch bits, test bits, and CRC check bits). Based on this formula, the intelligent driving domain controller can directly locate the physical hardware address for reading and writing, avoiding traversal lookups.

[0085] The system monitors the vehicle's ignition signal (IG signal) in real time. When the ignition signal changes from ON to OFF (i.e., the vehicle is powered off), the intelligent driving domain controller triggers the power-off storage process.

[0086] During the power-down storage process, the intelligent driving domain controller first reads the currently logged-in account ID and account type. If it determines that the current account belongs to a preset normal user account (e.g., ID range 1 to 9), the intelligent driving domain controller writes the current intelligent driving function switch status (on or off) of that account in the running memory (RAM) to the corresponding address in the non-volatile memory. This write operation ensures that the user's personalized settings are not lost when the vehicle is completely powered off and in sleep mode. When the vehicle is powered on again and the user logs in again, the intelligent driving domain controller reads the data at that storage address and automatically restores the function switches to the state before the last power-down, achieving seamless memory management.

[0087] If the intelligent driving domain controller determines that the current account belongs to a preset restricted user account, the system executes a volatile handling strategy. Restricted user accounts specifically include accounts with ID 0 and account type identified as Valet Mode or Guest. For such accounts, when the vehicle is powered off, the intelligent driving domain controller either does not save the current on / off setting or forcibly resets the corresponding status bit in memory to the default OFF state. The intention of this strategy is that when the owner hands the vehicle over to a valet parking attendant or lends it to someone for temporary use, even if the temporary user activates the intelligent driving function, the function will automatically reset to OFF once the vehicle is turned off and restarted. This effectively prevents the next driver from unknowingly triggering the intelligent driving function, thereby eliminating potential safety hazards.

[0088] In addition, this system defines special permission accounts with the highest priority, mainly including production line test accounts (Factory Mode, type code 0x03) and experience mode accounts (Experience Mode, type code 0x04). For these accounts, the system is configured to bypass all test status check logic. When the cockpit domain controller recognizes the login account as a special permission account, regardless of the test status records locally or in the cloud, the cockpit domain controller skips the steps of querying the cloud and displaying the QR code, and directly unlocks the permission to enable the intelligent driving function.

[0089] Specifically, for production line testing accounts, this logic allows workers to quickly test intelligent driving functions without scanning codes during the vehicle off-line inspection phase; for experience mode accounts (typically used for display or test drive vehicles), this logic allows sales personnel to demonstrate functions without binding their personal mobile phones. Although these two types of accounts skip the examination check, they also follow the logic of restricted users in terms of power-off memory strategy, that is, the switch state is not remembered or is automatically reset after power-off to ensure the consistency of the initial state for each demonstration or test.

[0090] The intelligent driving domain controller is also equipped with a data verification mechanism (CRC check) to verify data integrity when reading the stored state in non-volatile memory. If corrupted stored data or verification failure is found during the vehicle power-on reading phase, the intelligent driving domain controller will perform a fail-safe operation, forcibly resetting the function switch status of all accounts to off, and sending a data anomaly fault code to the cockpit domain controller to prompt the user to perform a system check. Through the above hierarchical strategy and storage protection mechanism, the system achieves flexible and secure intelligent driving function management.

[0091] See attached document Figure 4 This invention provides an in-vehicle intelligent driving safety learning and testing system. At the physical layer, the system includes a cockpit domain controller and an intelligent driving domain controller connected via an in-vehicle Ethernet or CAN bus, and a cloud server connected via a wireless network. To implement the above-described process, each controller is logically configured with multiple functional modules that perform specific tasks. These modules are instantiated by a processor executing computer program instructions from memory.

[0092] The cockpit domain controller integrates a human-machine interface module, a logic arbitration module, and a cloud communication module. The human-machine interface module is configured to drive the in-vehicle central control screen, rendering virtual switch controls for intelligent driving functions, disclaimer pop-ups, and location authorization pop-ups. This module also includes a QR code generation engine, used to generate QR code images in real time based on the exam link address sent from the cloud server, and display them as a modal window overlay on the current interface. The cloud communication module is configured to manage the data link of the in-vehicle communication terminal (T-BOX), responsible for encapsulating HTTP / HTTPS request messages, initiating account status query and polling requests to the cloud server, and parsing the JSON or XML response data returned by the cloud.

[0093] The core of the cockpit domain controller is the logic arbitration module, which is configured to execute the central decision-making logic for activating intelligent driving functions. Specifically, after receiving the user's activation command, the logic arbitration module first calls the account service interface to obtain the currently logged-in user's account ID, and then transmits this account ID to the intelligent driving domain controller via the in-vehicle communication protocol stack. This module is equipped with a state comparator to compare the local test status fed back by the intelligent driving domain controller with the cloud test status obtained by the cloud communication module. When a QR code test is required, the logic arbitration module starts an independent polling timer, triggering a cloud query at a preset period (e.g., 2000ms). After detecting a passed test status, it automatically schedules the human-machine interaction module to close the QR code and sends a status synchronization command and a function activation command to the intelligent driving domain controller.

[0094] The intelligent driving domain controller integrates a non-volatile memory management module and a function execution control module. The non-volatile memory management module directly interfaces with the underlying EEPROM or Flash memory, maintaining a local database indexed by account ID and with on / off status and exam pass bits as values. This module is configured to quickly retrieve the local database and return the results when receiving a query request from the cockpit domain controller; upon receiving a status update command, it performs an atomic write operation to ensure data persistence. Specifically, this module has built-in power-down protection logic. When the vehicle receives a power-off signal (IG OFF), it automatically writes the current status data in the running memory to the non-volatile memory and implements a policy of not storing or forcibly resetting for valet mode accounts.

[0095] The Function Execution Control Module is configured to respond to the EnableSignal command sent by the cockpit domain controller. When this command is enabled, the Function Execution Control Module activates the intelligent driving algorithm stack, including perception fusion, path planning, and motion control subsystems, enabling the vehicle to enter assisted driving mode. If the non-volatile memory management module reports a failed local test, the Function Execution Control Module disables the enable command at the underlying logic level, ensuring driving safety from the execution end.

[0096] The cloud server hosts a user rights database and an online examination service module. The user rights database stores the security learning and examination records of all users and supports high-concurrency query requests. The online examination service module is configured to provide an examination front-end page in H5 or mini-program format to mobile terminals, responsible for distributing test questions, verifying answers, and automatically scoring. When a user submits their answer sheet via mobile terminal and receives a passing score, this module immediately updates the status field in the rights database so that the cockpit domain controller's polling requests can obtain the passing result in real time.

[0097] Through the collaborative work of the above modules, this system constructs a secure closed loop integrating the edge and cloud: the cockpit domain controller is responsible for interaction and cloud synchronization, the intelligent driving domain controller is responsible for local storage and policy execution, and the cloud server is responsible for data center management. This distributed architecture leverages the immediacy of cloud data while ensuring the local availability of the vehicle in offline environments.

[0098] See attached document Figure 5 This hardware architecture can be applied to the cockpit domain controller, intelligent driving domain controller, or cloud server in the above embodiments. As shown in the figure, the electronic device includes: at least one processor, a communication interface, a memory, and a communication bus. The processor, communication interface, and memory communicate with each other via the communication bus.

[0099] The processor may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention, such as a digital signal processor (DSP) or a field-programmable gate array (FPGA). In automotive scenarios, for cockpit domain controllers, the processor is typically a high-performance SoC chip (such as Qualcomm Snapdragon series or Renesas R-Car series), with powerful graphics rendering and multitasking capabilities; for intelligent driving domain controllers, the processor is typically an AI chip with high computing power (such as NVIDIA Orin or Horizon Robotics Journey series), focusing on deep learning model inference and real-time control.

[0100] The memory may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device, flash memory, or embedded multimedia card (eMMC). The memory stores computer programs or instruction code, and the processor is configured to perform the various steps in the above method embodiments by calling the programs or instructions stored in the memory.

[0101] Specifically, when the electronic device is a cockpit domain controller, the processor executes the following steps when running the computer program: responding to the activation operation to obtain account information, querying the local status from the intelligent driving domain controller, initiating a query to the cloud if the local status fails, controlling the display screen to show the exam QR code if the cloud status also fails, starting a background polling thread, and synchronizing the passing result to the intelligent driving domain controller. When the electronic device is an intelligent driving domain controller, the processor executes the following steps when running the computer program: receiving the account ID and querying the exam status field in the local non-volatile memory, and responding to the cockpit domain controller's synchronization command to update.

[0102] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for learning and testing vehicle-mounted intelligent driving safety, characterized in that, Includes the following steps: S1. In response to the activation operation of the intelligent driving function on the cockpit domain controller, the cockpit domain controller obtains the account information of the currently logged-in user and synchronously sends the account information to the intelligent driving domain controller connected to it, requesting to obtain the local test status corresponding to the account information; S2. The cockpit domain controller receives the local test status fed back by the intelligent driving domain controller. The local test status is obtained by the intelligent driving domain controller querying locally stored data after receiving the account information. S3. If the local exam status is passed, the cockpit domain controller executes the function activation process. S4. If the local exam status is "failed", the cockpit domain controller requests the cloud exam status from the cloud server. S5. If the cloud-based exam status is "passed", the cockpit domain controller will synchronously send the cloud-based exam status to the intelligent driving domain controller for local storage update, and execute the function activation process. S6. If the cloud-based exam status is "failed", the cockpit domain controller will control the display of the exam QR code. After obtaining the updated exam pass result from the cloud, the exam pass result will be synchronously sent to the intelligent driving domain controller for local storage update, and the function activation process will be executed.

2. The vehicle-mounted intelligent driving safety learning and testing method according to claim 1, characterized in that, In step S6, after obtaining the updated exam pass result from the cloud, the exam pass result is synchronously sent to the intelligent driving domain controller for local storage update, and the function activation process is executed, including: After the exam QR code is displayed, the cockpit domain controller sends a polling request to the cloud server at a preset period to obtain the real-time cloud exam status. When the cloud server sends a message indicating that the cloud-based exam status is "passed," the cockpit domain controller closes the exam QR code and sends a synchronization signal containing the exam pass result to the intelligent driving domain controller. The cockpit domain controller receives the confirmation signal from the intelligent driving domain controller after completing the local storage update, and then executes the function activation process.

3. The vehicle-mounted intelligent driving safety learning and testing method according to claim 2, characterized in that, In step S6, after displaying the exam QR code, the following steps are also included: If the cockpit domain controller does not receive the cloud exam status from the cloud server within a preset time period, or receives access failure information from the cloud server, the cockpit domain controller will output a network error message on the display interface of the exam QR code. If the cockpit domain controller receives a user's instruction to close the exam QR code, it stops sending the polling request to the cloud server.

4. The vehicle-mounted intelligent driving safety learning and testing method according to claim 3, characterized in that, The execution function activation process includes: The cockpit domain controller outputs a disclaimer page; In response to the user's confirmation on the disclaimer page, the cockpit domain controller outputs a location authorization request pop-up window; In response to the user's authorization confirmation operation on the location authorization request pop-up, the cockpit domain controller displays the status of the intelligent driving function as enabled and sends a function activation command to the intelligent driving domain controller.

5. The vehicle-mounted intelligent driving safety learning and testing method according to claim 1, characterized in that, Prior to step S1, the method further includes a vehicle power-on initialization process: In response to the vehicle power-on signal, the cockpit domain controller synchronously sends the currently logged-in account information to the intelligent driving domain controller; The intelligent driving domain controller queries the locally stored switch memory status based on the account information and feeds back the switch memory status to the cockpit domain controller; The cockpit domain controller updates the on / off display status of the intelligent driving function based on the switch memory status; The cockpit domain controller requests the latest cloud-based exam status from the cloud server, and if the cloud-based exam status is inconsistent with the local storage data of the intelligent driving domain controller, the cloud-based exam status is synchronously sent to the intelligent driving domain controller for local storage update.

6. The vehicle-mounted intelligent driving safety learning and testing method according to claim 5, characterized in that, The process of querying the locally stored switch memory status by the intelligent driving domain controller based on the account information includes: If the account information belongs to a preset normal user account, the intelligent driving domain controller reads the switch setting state stored before the last time the vehicle was powered off as the switch memory state. If the account information belongs to a preset restricted user account, the intelligent driving domain controller will reset the switch memory state to the default off state. The restricted user account includes valet mode accounts or accounts that are not logged in.

7. The vehicle-mounted intelligent driving safety learning and testing method according to claim 6, characterized in that, It also includes processing procedures for pre-defined accounts with special permissions: If the account information belongs to a preset special permission account, the cockpit domain controller will not execute steps S2 to S6, but will directly execute the function activation process. The special permission accounts include production line testing accounts or experience mode accounts.

8. The vehicle-mounted intelligent driving safety learning and testing method according to claim 5, characterized in that, Also includes: In response to the vehicle power-off signal, the intelligent driving domain controller determines whether the current account information belongs to a normal user account; If so, the intelligent driving domain controller will associate the current switch setting state of the intelligent driving function with the account information and store it locally, so as to restore the switch setting state when the vehicle is powered on again.

9. A vehicle-mounted intelligent driving safety learning and testing system, characterized in that, The method for learning and testing vehicle-mounted intelligent driving safety as described in any one of claims 1-8 includes: a cockpit domain controller, an intelligent driving domain controller, and a cloud server; The cockpit domain controller includes an interactive arbitration module, used to respond to the activation operation of the intelligent driving function, obtain the account information of the currently logged-in user, and request the local test status from the intelligent driving domain controller; execute a logical decision based on the local test status fed back by the intelligent driving domain controller, if the local test is passed, execute the function activation process, if the local test is not passed, request the cloud test status from the cloud server; and when the cloud test is passed, synchronously send the status to the intelligent driving domain controller, or when the cloud test is not passed, control the display of the test QR code and execute a polling query against the cloud server until a passing result is obtained, triggering the synchronization and activation process; The intelligent driving domain controller includes a local storage management module, which is used to query the examination status or switch memory status corresponding to the account information in the local non-volatile memory and provide feedback in response to a request from the cockpit domain controller; and to write the latest examination pass result into the local non-volatile memory in response to a synchronization signal from the cockpit domain controller; the local storage management module is also configured to perform power-off retention or forced reset operation of the switch status when the vehicle is powered off or powered on, depending on whether the account information belongs to a normal user account or a restricted user account. The cloud server includes an exam data service module, which is used to maintain users' exam pass records and respond to query requests or periodic polling requests from the cockpit domain controller to provide real-time cloud exam status feedback.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 8.