A rescue method and apparatus

CN122501274APending Publication Date: 2026-08-04YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
YINWANG INTELLIGENT TECHNOLOGIES CO LTD
Filing Date
2026-06-29
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

例如,车辆在下沉过程中,因车辆外部水压迅速增大,导致车门难以打开,从而阻断乘员的逃生

Benefits of technology

[0052] The second to seventh aspects of this application correspond to the technical solutions of the first aspect of this application. The beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be repeated here.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122501274A_ABST
    Figure CN122501274A_ABST
Patent Text Reader

Abstract

The application provides a rescue method and device, and relates to the technical field of driving equipment. In the method, at least two of the following information is analyzed: environment information of the driving equipment, body external perception information of the driving equipment, pose information of the driving equipment, motion state information of the driving equipment, environment information in the cabin of the driving equipment, and behavior information of the passengers. From the multiple rescue strategies, a suitable rescue strategy is determined. In this way, the real situation of the driving equipment falling into water can be obtained, the misjudgment rate is reduced, and thus the suitable rescue strategy is determined from the multiple preset rescue strategies, which helps to improve the survival rate of the passengers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of driving equipment, and more particularly to a rescue method and apparatus. Background Technology

[0002] Although the incidence of accidents involving driving equipment falling into water is lower than that of collisions, the fatality rate of such accidents is extremely high, posing a significant safety hazard to driving equipment. Taking vehicles as an example, after a vehicle falls into water, occupants face multiple fatal threats. For instance, as the vehicle sinks, the rapid increase in external water pressure makes it difficult to open the doors, thus preventing occupants from escaping. Another example is that after a vehicle falls into water, the vehicle's high-voltage circuitry may short-circuit due to water immersion, potentially causing an electric shock risk.

[0003] How to take appropriate rescue measures has become a technical problem that urgently needs to be solved. Summary of the Invention

[0004] This application provides a rescue method and apparatus in order to determine a suitable rescue strategy and improve the survival rate of occupants.

[0005] Firstly, this application provides a rescue method, the steps of which can be performed by a rescue device. The rescue device can be the driving equipment itself, or it can be a component configured in the driving equipment (such as a chip, chip system, processor, or controller), or it can be a logic module or software implementation capable of realizing all or part of the functions of the driving equipment; the embodiments of this application do not limit this.

[0006] For example, the driving device could be a vehicle.

[0007] The method includes: acquiring first perception data, which includes at least two of the following: environmental information of the first driving device, external perception information of the main body of the first driving device, position and posture information of the first driving device, motion state information of the first driving device, environmental information inside the cabin of the first driving device, occupant behavior information, and occupant physiological state information; and executing a first rescue strategy based on the first perception data, which is one of multiple rescue strategies.

[0008] Based on the above technical solution, by analyzing at least two of the following: environmental information of the driving equipment, external sensory information of the driving equipment, posture information of the driving equipment, motion state information of the driving equipment, environmental information inside the driving equipment cabin, and occupant behavior information, a suitable rescue strategy is determined from multiple rescue strategies. The use of multi-dimensional heterogeneous sensors to collect rich and diverse sensory data allows for multi-faceted analysis of whether the first driving equipment is submerged or has fallen into water, helping to reduce the false alarm rate. Determining a suitable rescue strategy (e.g., a first rescue strategy) from multiple preset rescue strategies helps improve the success rate of occupant rescue, thereby increasing the occupant survival rate.

[0009] In conjunction with the first aspect, in some possible implementations, a first rescue strategy is executed based on the first perception data, including: determining the first water level of the first driving device from multiple water level classifications based on the first perception data; determining the first rescue strategy corresponding to the first water level from the multiple rescue strategies based on the first water level; and executing the first rescue strategy.

[0010] A simple implementation method is provided to analyze sensing data, determine the water level of the first driving device, and then determine the corresponding rescue strategy based on the water level of the first driving device. The implementation method is simple and has good universality.

[0011] In conjunction with the first aspect, in some possible implementations, the first water-fall level is determined based on a water-fall score and a first correspondence relationship, which includes multiple sets of correspondence relationships between water-fall score intervals and water-fall levels. The water-fall score is determined based on the first sensing data and is used to indicate the degree of water-fall risk of the first driving device.

[0012] Quantifying the water-fall status of the first driving device based on perception data and obtaining a water-fall score for the first driving device helps to refine the water-fall status of the first driving device and determine the water-fall level of the first driving device, thereby improving the accuracy of judging whether the driving device has fallen into the water and reducing the false judgment rate.

[0013] In conjunction with the first aspect, in some possible implementations, if the water score is greater than or equal to a first threshold, the first rescue strategy is used to instruct the occupant to wait for rescue in the first driving device; or, if the water score is less than the first threshold but greater than or equal to a second threshold, the first rescue strategy is used to instruct the occupant to escape from the first driving device.

[0014] Based on the water-fall score of the pilot equipment, rescue strategies are divided into two main categories: instructing the occupant to wait for rescue in the primary pilot equipment (referred to as waiting for professional rescue) and instructing the occupant to escape from the primary pilot equipment (referred to as active escape). In practical applications, targeted rescue strategies can be implemented according to the actual water-fall situation of the pilot equipment, thereby helping to improve the survival rate of the occupants.

[0015] In conjunction with the first aspect, in some possible implementations, if the water score is greater than or equal to the first threshold, the first water level is level 3. The first rescue strategy corresponding to level 3 includes: controlling the first driving device to be in a sealed state; releasing a buoy and sending a first distress signal through the buoy, the first distress signal being used to request rescue of the first driving device, the first distress signal including the identifier of the first driving device and the location information of the first driving device; and providing oxygen to the occupant.

[0016] In cases where the vehicle's equipment is submerged in water at a high level, such as Level 3, sealing the equipment, such as by completely closing the doors and windows, can reduce the rate at which water enters the cabin and provide oxygen to the occupants, thereby helping to improve their survival rate.

[0017] In conjunction with the first aspect, in some possible implementations, when the water score is less than the first threshold and greater than or equal to the third threshold, the first water level is level 2. The first rescue strategy corresponding to level 2 includes: controlling all door locks of the first driving device to be unlocked; controlling the window of the first driving device to descend to the lowest height supported by the window; sending a second distress message, which requests rescue for the first driving device, and the second distress message includes the identifier of the first driving device and the location information of the first driving device; wherein, the third threshold is greater than the second threshold and the third threshold is less than the first threshold.

[0018] If the water immersion level of the driving equipment is not too high, such as level 2, timely prompting of occupants to escape can help them get out of the equipment in time, reducing the probability of them sinking with the equipment and thus improving their survival rate.

[0019] In conjunction with the first aspect, in some possible implementations, when the water score is less than the third threshold and greater than or equal to the second threshold, the first water level is level 1, and the first rescue strategy corresponding to level 1 includes: outputting a first alarm message, which is used to indicate that the first driving device has a risk of water immersion; wherein the third threshold is greater than the second threshold and the third threshold is less than the first threshold.

[0020] In cases where the water level of the driving equipment is low, such as Level 1, timely alerting of the occupants to the risk of the equipment entering water and early intervention can help reduce the probability of the equipment falling into the water.

[0021] In conjunction with the first aspect, in some possible implementations, the first distress message may also include first information, which may include one or more of the following: the water depth of the first driving device, the attitude of the first driving device, the number of occupants on the first driving device, the location information of the occupants, the physiological state information of the occupants, and a recommended rescue location for rescuing the occupants.

[0022] Indicating the attitude of the first driving equipment by sending a distress signal helps the rescuer to take appropriate rescue measures based on the attitude of the first driving equipment, thereby helping to improve the success rate of the rescue.

[0023] Indicating the number of occupants on the first operating device via the first distress message helps the rescuer understand the number of occupants awaiting rescue on that first operating device, thereby enabling them to prepare sufficient rescue supplies.

[0024] Indicating the occupants' location information through the first distress message helps the rescuer understand the number of occupants awaiting rescue and their locations, thereby enabling them to prepare sufficient rescue supplies. Furthermore, the location information of each occupant helps to shorten the rescue time, thus contributing to a higher success rate of the rescue.

[0025] Instructing rescuers to provide information on the physiological status of the occupants on the first driving device via a first distress signal helps them determine whether there are any occupants still showing signs of life on that device.

[0026] The first distress signal indicates the recommended rescue location for each occupant, which helps the rescuer to provide reference information for rescuing the occupants on the first driving equipment. This helps the rescuer to quickly take appropriate rescue measures, thereby improving the success rate of the rescue.

[0027] In conjunction with the first aspect, in some possible implementations, the first rescue strategy corresponding to level 3 further includes: sending second information to the buoy according to a first cycle, the second information including one or more of the following: the location information of the first driving device, the water depth of the first driving device, the attitude of the first driving device, the physiological state information of the occupant, and the recommended rescue location for rescuing the occupant.

[0028] By periodically sending a second message to the buoy, the buoy can update the relevant information in the first distress message based on the latest information of the first driving device. This helps rescuers, such as the rescue center, to obtain the latest information of the first driving device, so as to adjust the rescue plan in a timely manner and take more appropriate rescue methods.

[0029] In conjunction with the first aspect, in some possible implementations, when the first water level is level 2 or level 3 and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: controlling the first power module to power off and controlling the second power module of the first driving device to power on; wherein the first power module is used to supply power to the drive motor of the first driving device, and the second power module is used to supply power to the first driving device in the event that the first power module malfunctions or is in an abnormal state.

[0030] If necessary, the rescue device can promptly de-energize the first power module, reducing the risk of electric shock to occupants due to short circuits caused by water immersion.

[0031] In conjunction with the first aspect, in some possible implementations, when the first water level is level 1 and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: outputting a second alarm message, the second alarm message being used to indicate that the first power module is in an unhealthy state; wherein, the first power module is used to supply power to the drive motor of the first driving device.

[0032] The second alarm message alerts occupants to the health status of the first power module. This helps occupants understand the health of the first power module as early as possible, allowing them to take preventative measures and reduce safety risks caused by a failure of the first power module.

[0033] In conjunction with the first aspect, in some possible implementations, the method further includes: detecting the health status of the first power module when the risk of the first driving device falling into the water is determined to be greater than or equal to a fourth threshold based on the environmental information, and / or when the probability of the first driving device malfunctioning is determined to be greater than or equal to a fifth threshold based on the pose information and the motion state information.

[0034] If a high risk of the first driving device falling into the water is detected, and / or the probability of the driving device going out of control is relatively high, timely activation of the health status of the first power module of the driving device can help prepare to power down the first power module as early as possible before a safety accident occurs, thereby helping to reduce the risk of secondary injury to the occupants caused by the failure of the first power module.

[0035] In conjunction with the first aspect, in some possible implementations, the rescue strategy corresponding to level 3 also includes: sending a third distress message to the second driving device, the third distress message including the identifier of the first driving device and the location information of the first driving device, the third distress message being used to request rescue of the first driving device.

[0036] After the first driving device falls into the water, it can also send a distress signal to other driving devices that have fallen into the water. The other driving devices can then help forward the distress signal so that the distress signal from the first driving device can be transmitted to the rescuers (such as the rescue center) in a timely manner, thereby helping to improve the survival rate of the occupants of the first driving device.

[0037] In conjunction with the first aspect, in some possible implementations, the rescue strategy corresponding to Level 3 further includes: obtaining a fourth distress message from the third driving device, the fourth distress message including the identifier of the third driving device and the location information of the third driving device, the fourth distress message being used to request rescue of the third driving device; and sending the fourth distress message to the buoy.

[0038] After the first driving device falls into the water, it can also receive distress signals from other driving devices that have fallen into the water, and assist other driving devices in forwarding distress signals so that the distress signals from other driving devices can be transmitted to the rescuers (such as the rescue center) in a timely manner, thereby helping to improve the survival rate of the occupants of other driving devices.

[0039] In conjunction with the first aspect, in some possible implementations, the method also includes sending the first sensing data to a cloud server.

[0040] The first driving device can send the first perception data to the cloud server so that the cloud server can iteratively update the algorithms or models related to the rescue method.

[0041] Secondly, this application provides a rescue device, including modules or units for implementing the methods of the first aspect and any possible implementation thereof. Each module or unit can implement its corresponding function by executing a computer program.

[0042] Thirdly, this application provides a rescue device including a processor that can be coupled to a memory and can be used to execute a program in the memory to implement the execution steps in the first aspect and any possible implementation of the first aspect.

[0043] Optionally, the rescue device also includes a memory.

[0044] Optionally, the rescue device also includes a communication interface, to which the processor is coupled.

[0045] Fourthly, this application provides a driving device that includes a rescue device as described in the second or third aspect.

[0046] Alternatively, the driving device can be a vehicle.

[0047] For example, a vehicle may include one or more of the following: a car, a truck, a van, a bus, an entertainment vehicle, a playground vehicle, a golf cart, etc.

[0048] Fifthly, this application provides a computer-readable storage medium storing a computer program or instructions that, when executed on a computer, cause the computer to perform the methods described in the first aspect or any possible implementation thereof.

[0049] Sixthly, this application provides a computer program product including a computer program, which, when run on a computer, causes the computer to perform the methods described in the first aspect or any possible implementation of the first aspect.

[0050] Seventhly, this application provides a chip or chip system including at least one processor and a communication interface, wherein the communication interface and at least one processor are interconnected via a circuit, and the at least one processor is used to run a computer program or instructions to perform the methods described in the first aspect or any possible implementation thereof. The communication interface in the chip may be an input / output interface, pins, or circuits, etc.

[0051] In one possible implementation, the chip or chip system described above in this application further includes at least one memory storing instructions. The memory can be an internal storage unit of the chip, such as a register or cache, or it can be a storage unit of the chip itself (e.g., read-only memory, random access memory, etc.).

[0052] The second to seventh aspects of this application correspond to the technical solutions of the first aspect of this application. The beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be repeated here. Attached Figure Description

[0053] Figure 1 This is a functional block diagram of a driving device provided in an embodiment of this application;

[0054] Figure 2 This is a schematic diagram of the architecture of the driving system provided in the embodiments of this application;

[0055] Figure 3 This is a schematic flowchart of the rescue method provided in the embodiments of this application;

[0056] Figure 4 This is a schematic diagram illustrating the calculation of the water score provided in an embodiment of this application;

[0057] Figure 5 This is a schematic flowchart illustrating the detection of the health status of the first power module provided in an embodiment of this application;

[0058] Figure 6 This is a schematic diagram of a rescue strategy that combines the physiological state of the occupants, as provided in an embodiment of this application.

[0059] Figure 7 This is a schematic diagram of the underwater acoustic link network provided in an embodiment of this application;

[0060] Figure 8 This is a schematic diagram of model iteration based on digital twin provided in an embodiment of this application;

[0061] Figure 9 This is a schematic structural diagram of the rescue device provided in the embodiments of this application;

[0062] Figure 10 This is another schematic block diagram of the rescue device provided in the embodiments of this application;

[0063] Figure 11 This is another schematic block diagram of the rescue device provided in the embodiments of this application. Detailed Implementation

[0064] To facilitate understanding of the embodiments of this application, the following points will be explained first:

[0065] First, in the embodiments of this application, the indication includes explicit indication (also known as direct indication) and implicit indication (also known as indirect indication). Explicit indication information A refers to including information A; implicit indication information A refers to indicating information A through the correspondence between information A and information B and direct indication information B. The correspondence between information A and information B can be predefined, pre-stored, pre-burned, or pre-configured; or it can refer to indicating information A through information B and preset rules.

[0066] Second, in the embodiments of this application, information C is used to determine information D, which includes determining information D based solely on information C, as well as determining it based on information C and other information. Furthermore, information C can also be used to determine information D indirectly, for example, in the case where information D is determined based on information E, and information E is determined based on information C.

[0067] Third, in the embodiments of this application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates an "or" relationship between the preceding and following related objects, but it does not exclude the possibility of indicating an "and" relationship. The specific meaning can be understood in conjunction with the context. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c; a and b; a and c; b and c; or a and b and c. Here, a, b, and c can be single or multiple.

[0068] Fourth, in the embodiments of this application, the use of prefixes such as "first" and "second" is merely for the purpose of distinguishing and describing different things belonging to the same name category, and does not constrain the order, size, or quantity of things. For example, "first threshold" and "second threshold" are simply different thresholds, and there is no temporal order, size, or priority relationship between them.

[0069] Fifth, the "sending" and "receiving" in the embodiments of this application can be performed between devices, such as between a second device and a first device; or they can be performed within a device, such as between components, modules, chips, software modules, or hardware modules within a device via a bus, wiring, or interface.

[0070] Sixth, in the embodiments of this application, "when," "if," and "if" all refer to the device making corresponding processing under certain objective circumstances, and are not limited to a time, nor do they require the device to make a judgment action when it is implemented, nor do they mean that there are other limitations.

[0071] Seventh, in the embodiments of this application, the words "example," "exemplarily," "for example," or "such as" are used to indicate that they are examples, illustrations, or explanations. Any embodiment or design that is described as "example," "exemplarily," "for example," or "such as" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Specifically, the use of the words "example," "exemplarily," "for example," or "such as" is intended to present the relevant concepts in a specific manner.

[0072] Eighth, in the embodiments of this application, when configuring each correspondence (e.g., the first correspondence), it is not necessarily required that each correspondence be configured in the form of a mapping table (or table). Other data structures can also be used, such as arrays, queues, containers, stacks, linear lists, pointers, linked lists, trees, graphs, structures, classes, heaps, hash tables, or hash tables. The embodiments of this application do not impose any limitations on this.

[0073] Furthermore, in the embodiments of this application, each correspondence can also be in functional form. That is, a certain term in a correspondence can be calculated based on other terms except for that term using the function. The function used to represent the correspondence can be a linear function or a nonlinear function. The embodiments of this application do not impose any limitations on this.

[0074] To facilitate understanding of the embodiments of this application, some technical terms or vocabulary involved in the embodiments of this application will be briefly explained below.

[0075] 1. Buoy

[0076] In the embodiments of this application, the buoy may refer to a dedicated underwater rescue positioning system for driving equipment or an automatic alarm positioning device.

[0077] In practical applications, the buoy is not only a buoyancy-providing device but also an intelligent safety device integrating multiple functions. The buoy can be mounted on top of the driving equipment and connected to the main body of the equipment via a tow rope. When the driving equipment is operating normally, the buoy is in a preset retracted state. If the driving equipment detects a risk of falling into the water, it can unlock the buoy, allowing it to float to the surface.

[0078] Buoys can be made of bright colors (such as red, orange-red, etc.) and equipped with highly visible reflective strips so that rescue vessels or helicopters can quickly spot the buoy in low visibility or turbulent waters, thereby narrowing the search area for the rescue target.

[0079] Some buoys can also provide grab points or temporary buoyancy support for occupants who successfully escape from the vehicle, helping them reduce heat loss while waiting for professional rescue.

[0080] In one possible implementation, the buoy may contain a water-fall detection module for the driving equipment (such as a moisture sensor, pressure sensor, etc.). When the water-fall detection module detects that the driving equipment has entered the water or is in a water-falling state, it will trigger the control module of the driving equipment to release the buoy, causing the buoy to automatically float to the water surface.

[0081] In practical applications, buoys can also include positioning modules (such as Global Positioning System (GPS)) and wireless communication modules (or alarm positioning components). After the buoy surfaces, it can send the coordinates of the submerged equipment and distress signals to the outside world (such as a rescue center).

[0082] Using a vehicle as an example of a driving device, the buoy can be placed in the vehicle's roof, sunroof, or trunk.

[0083] 2. Digital twin

[0084] In this application embodiment, digital twin refers to the construction of a dynamic model in virtual space that highly corresponds to a physical entity (such as a vehicle or road environment) through digital means. This model can reflect the state and behavior of the physical entity in real time.

[0085] 3. Theory of Belief Functions

[0086] The confidence function theory is a set function theory based on the power set of the frame of discernment and satisfying specific monotonicity (or additivity) axioms.

[0087] The confidence function theory, also known as the Dempster-Shafer (DS) evidence theory, is a mathematical framework for dealing with uncertainty, established by Arthur Dempster and Glenn Shafer.

[0088] 4. Basic probability assignment (BPA)

[0089] BPA is the most core and fundamental building block of DS evidence theory. In other words, BPA is the derivative or fundamental particle of DS evidence theory; once BPA is known, all other functions in the entire DS evidence theory system can be uniquely derived.

[0090] Although the incidence of accidents involving driving equipment falling into water is lower than that of collisions, the fatality rate of such accidents is extremely high, posing a significant safety hazard to driving equipment. Taking vehicles as an example, after a vehicle falls into water, occupants face multiple fatal threats. For instance, as the vehicle sinks, the rapid increase in external water pressure makes it difficult to open the doors, thus preventing occupants from escaping. Another example is that after a vehicle falls into water, the vehicle's high-voltage circuitry may short-circuit due to water immersion, potentially causing an electric shock risk.

[0091] Currently known solutions for detecting vehicle submersion in water rely on single sensor data to determine if the vehicle has fallen into water, resulting in a high false alarm rate and an inability to distinguish between passing through puddles and being submerged in water. Furthermore, current rescue methods are limited in scope; for example, after determining submersion, the vehicle lowers its windows to the lowest possible level without considering the actual environment in which the vehicle is located, leading to a low survival rate for occupants.

[0092] Therefore, how to take appropriate rescue measures has become a technical problem that urgently needs to be solved.

[0093] To address the aforementioned technical problems, this application provides a rescue method that analyzes at least two of the following: environmental information of the driving equipment, external sensory information of the driving equipment, the posture information of the driving equipment, the motion state information of the driving equipment, environmental information inside the driving equipment's cabin, and occupant behavior information. From multiple rescue strategies, a suitable rescue strategy is determined. This method, by analyzing information about the driving equipment's environment, its own state, or the occupant's behavior, helps to obtain the true situation of the driving equipment falling into the water, reducing the misjudgment rate and thus determining a suitable rescue strategy from multiple preset options, thereby improving the occupant's survival rate.

[0094] Before describing the rescue method provided in the embodiments of this application, the following will first combine... Figure 1 and Figure 2 The driving equipment and driving system applicable to the methods provided in this application will be described separately.

[0095] Figure 1 This is a functional block diagram of a driving device provided in an embodiment of this application.

[0096] like Figure 1 As shown, the driving device 100 may include a perception system 110, a computing platform 120, and a communication device 130.

[0097] The perception system 110 may include several types of sensors for sensing information about the environment surrounding the driving device 100. For example, the perception system 110 may include a positioning system, such as a global navigation satellite system (GNSS), GPS, or BeiDou. Alternatively, the perception system 110 may also include one or more of the following: an inertial measurement unit (IMU), lidar, millimeter-wave radar, ultrasonic radar, pressure sensor, rain sensor, humidity sensor, and camera device.

[0098] The sensing system 110 may also include a water level sensor (or a water depth sensor), which can be used to detect the water level height (or the height of other liquids besides water). In this embodiment, water is used as an example for description.

[0099] In one possible implementation, the water level sensor can be a sensor specifically designed to detect the presence of liquid and the water level height. Alternatively, the water level sensor can be an ultrasonic radar. That is, in this embodiment, the ultrasonic radar in the driving device 100 can be configured to detect water level height (or depth). In other words, the ultrasonic radar in the sensing system 110 can be used to detect both obstacles and water level height.

[0100] In the method provided in the embodiments of this application, the sensing system 110 includes several types of sensors that can be used to sense and acquire first sensing data. The first sensing data includes at least two of the following information: environmental information of the driving device, external sensing information of the main body of the driving device, position and posture information of the driving device, motion state information of the driving device, environmental information inside the cockpit of the driving device, and occupant behavior information.

[0101] Some or all of the functions of the driving device 100 can be controlled by the computing platform 120. The computing platform 120 may include processors 121 to 12n (n is an integer greater than or equal to 1), and the processor may be a circuit with signal processing capabilities.

[0102] In one implementation, the processor can be a circuit capable of reading and executing instructions, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a type of microprocessor), or a digital signal processor (DSP). In another implementation, the processor can achieve certain functions through the logical relationships of hardware circuits. These logical relationships are either fixed or reconfigurable. For example, the processor can be a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as a field-programmable gate array (FPGA). In reconfigurable hardware circuits, the process of the processor loading a configuration file and configuring the hardware circuit can be understood as the processor loading instructions to achieve the functions of some or all of the above units. Furthermore, the processor can also be a hardware circuit designed for artificial intelligence, which can be understood as a type of ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), or a deep learning processing unit (DPU).

[0103] In addition, the computing platform 120 may also include a memory that can be used to store instructions, and some or all of the processors 121 to 12n can call the instructions in the memory to perform the corresponding functions.

[0104] The computing platform 120 can control the operation of the driving system, which may include an advanced driving assistance system (ADAS) and an autonomous driving system (ADS). The driving system can utilize various sensors on the driving equipment (including but not limited to: LiDAR, millimeter-wave radar, cameras, ultrasonic sensors, GPS, and inertial measurement units) to acquire information from the surroundings of the driving equipment, and analyze and process the acquired information to achieve functions such as obstacle perception, target recognition, localization, path planning, and driver monitoring / alerts, thereby improving driving safety, automation, and comfort.

[0105] At different levels of autonomous driving (or intelligent driving levels, ranging from L0 to L5, six levels in total), intelligent driving systems can achieve different levels of automated driving assistance based on artificial intelligence algorithms and information acquired by multiple sensors. These autonomous driving levels are based on the classification standards of the Society of Automotive Engineers (SAE). Level L0 is no automation; Level L1 is driver assistance; Level L2 is partial automation; Level L3 is conditional automation; Level L4 is high automation; and Level L5 is full automation. At levels L1 to L3, the task of monitoring road conditions and reacting is jointly completed by the driver and the system, requiring the driver to take over dynamic driving tasks. Levels L4 and L5 allow the driver to completely transform into a passenger. Currently, the functions that intelligent driving systems can achieve include, but are not limited to: adaptive cruise control, automatic emergency braking, automatic parking, blind spot monitoring, forward cross-traffic alert / braking, rear cross-traffic alert / braking, forward collision warning, lane departure warning, lane keeping assist, rear collision warning, traffic sign recognition, traffic jam assist, and highway assist. It is understandable that the various functions mentioned above can have specific modes at different levels of autonomous driving (L0-L5), and the higher the level of autonomous driving, the more intelligent the corresponding mode.

[0106] For example, in the method provided in this application, the computing platform 120 can process and analyze the first sensing data obtained by the sensing system 110, and determine a suitable rescue strategy from a plurality of preset rescue strategies based on the analysis results.

[0107] The communication device 130 can be used to communicate with other devices, such as cloud servers. The communication device 130 may include, for example, a vehicle-to-everything (V2X) communication unit.

[0108] It should be understood that V2X may include, but is not limited to, one or more of the following communication methods: vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), vehicle-to-network (V2N), or vehicle-to-device (V2D). The network may include cellular networks; the device may include smartphones or other portable devices.

[0109] Therefore, the driving device 100 can communicate with other driving devices (or other vehicles) via the V2X communication unit, for example, to obtain distress signals from other driving devices. The driving device 100 can also obtain image data captured by cameras on other infrastructure via the V2X communication unit. The driving device 100 can also communicate with the cloud (or other devices) via the V2X communication unit.

[0110] For example, in this embodiment of the application, the driving device 100 can send first perception data to the cloud server through the V2X communication unit.

[0111] For example, in this embodiment of the application, the V2X communication unit of the driving device 100 may include a buoy, through which the driving device 100 can communicate with the rescue center to request the rescue center to rescue the driving device, etc.

[0112] In one possible implementation, the driving device 100 may also include a display device 140.

[0113] Optionally, the display device 140 can be divided into two categories. For example, the first category can be an in-vehicle display screen; the second category can be a projection display screen, such as a head-up display (HUD).

[0114] The in-vehicle display screen can be a physical display screen and is an important component of the in-vehicle infotainment system. Multiple displays can be installed in the cabin, such as digital instrument cluster displays and central control screens. In some possible implementations, one or more of the aforementioned in-vehicle displays can be human-machine interfaces (HMIs); for example, the central control screen can be an HMI.

[0115] Additionally, head-up displays (HUDs), also known as head-up display systems, are used to display driving information such as speed and navigation on a display device in front of the driver (e.g., on the windshield). This reduces driver eye movement time, avoids pupil dilation caused by eye shifts, and improves driving safety and comfort. HUDs can include, but are not limited to, combiner-HUD (C-HUD) systems, windshield-HUD (W-HUD) systems, and augmented reality HUD (AR-HUD) systems.

[0116] In practical applications, the driving device 100 can be a device mounted on a vehicle or the vehicle itself.

[0117] Figure 2 This is a schematic diagram of the architecture of the driving system provided in the embodiments of this application.

[0118] like Figure 2 As shown, the driving system 200 may include a perception module 210, a control module 220, a communication module 230, and a human-machine interaction module 240.

[0119] The sensing module 210 may include, for example: Figure 1 The perception system 110 shown includes one or more camera devices or one or more radar sensors for collecting environmental information about the area where the driving equipment is located, such as information about parking lines and obstacles.

[0120] The sensing module 210 may also include other sensors such as a water level sensor, a pressure sensor, a rainfall sensor, or a humidity sensor. See details for further information. Figure 1 For the sake of brevity, the relevant descriptions will not be repeated here.

[0121] The perception module 210 can also process the collected perception data. For example, the perception module 210 can build a world model consisting of roads, obstacles, etc. for downstream modules (such as the control module 220 and the human-computer interaction module 240).

[0122] The sensing module 210 can also send the sensing information it collects and / or determines to the control module 220. For example, in the method provided in this application, the sensors included in the sensing module 210 can be used to sense and acquire first sensing data, which includes at least two of the following: environmental information of the driving device, external sensing information of the main body of the driving device, position and pose information of the driving device, motion state information of the driving device, environmental information inside the cockpit of the driving device, and occupant behavior information, etc.

[0123] In this embodiment of the application, the control module 220 can be used to control the execution of a first rescue strategy, which is determined from a plurality of preset rescue strategies based on the first perception data.

[0124] Communication module 230 and Figure 1 The communication device 130 is similar, and can be referred to the description above, so it will not be repeated here.

[0125] The human-computer interaction module 240 may include, for example: Figure 1 One or more of the display devices 140 shown may include, for example, an HMI; the human-computer interaction module 240 may also include a sound-generating device (such as a speaker, audio device, etc.) and a sound-receiving device (such as a microphone).

[0126] In this embodiment, the human-machine interaction module 240 can output a first alarm message, which is used to indicate that the driving device is at risk of wading through water.

[0127] In one possible implementation, the driving system 200 may also include a display module 250.

[0128] The display module 250 may include, for example, Figure 1 One or more of the display devices 140 shown are included, and the display module 250 can display the vehicle's infotainment interface. The human-machine interaction module 240 can receive user commands (including voice commands, touchscreen commands, etc.) and then control the changes in the interface displayed by the display module 250 according to the commands. For a detailed description of the display module 250, please refer to the above. Figure 1 The relevant description of the display device 140 will not be repeated here.

[0129] The rescue method provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0130] Figure 3 This is a schematic flowchart of the rescue method provided in the embodiments of this application.

[0131] like Figure 3 As shown, method 300 may include steps S310 and S320. The following provides a detailed description of each step in method 300.

[0132] The steps of this method can be performed by a rescue device or a driving device. The rescue device can be a component configured in the driving device (such as a chip, chip system, processor, or controller, etc.), or it can be a logic module or software implementation capable of realizing all or part of the functions of the driving device; this application does not limit this.

[0133] As an example and not a limitation, the driving device can be a vehicle.

[0134] The following describes in detail each step of method 300, taking the execution of method 300 by a rescue device as an example.

[0135] S310, acquire first perception data, which includes at least two of the following: environmental information of the first driving device, external perception information of the main body of the first driving device, position and posture information of the first driving device, motion state information of the first driving device, environmental information inside the cabin of the first driving device, occupant behavior information, and occupant physiological state information.

[0136] For example, the rescue device can be deployed on the first driving device. The rescue device can be based on, for example... Figure 1 The sensing system 110 shown or Figure 2 The sensing module 210 shown acquires the first sensing data.

[0137] As an example and not a limitation, the environmental information of the first driving device may be collected by one or more of millimeter-wave radar, camera devices (or cameras), positioning systems or rain sensors.

[0138] For example, millimeter-wave radar and / or cameras can be used to identify whether liquids (such as water) are present in the environment in which the first driving device is located.

[0139] For example, a positioning system can identify whether the first driving device is off the road or in a low-lying area.

[0140] For example, a rain sensor can identify the intensity of rainfall, thereby determining whether there is liquid (such as water) in the environment where the first driving device is located.

[0141] Therefore, based on the environmental information of the first driving device, it can be determined whether the first driving device is at risk of being submerged in water or whether the first driving device has fallen into the water.

[0142] If the driving equipment passes through deep puddles or low-lying areas with standing water, the first driving equipment may be at risk of being submerged, but it does not necessarily fall into the water. If the first driving equipment falls into the water, the risk of submersion is greater.

[0143] As an example and not a limitation, the external sensing information of the primary driving device may be collected by one or more of a pressure sensor or a water level sensor.

[0144] For example, a pressure sensor deployed on the vehicle door can identify the external pressure exerted on the door of the first driving device. The pressure data obtained by the pressure sensor on the door differs depending on whether the door of the first driving device is submerged in water or not. Therefore, based on the pressure data collected by the pressure sensor on the door, it can be determined whether the first driving device is at risk of being submerged or whether it has fallen into water.

[0145] Without loss of generality, pressure data collected by pressure sensors deployed on the front and / or rear bumpers of the driving device can also be used to determine whether the first driving device is at risk of being submerged in water or whether the first driving device has fallen into water.

[0146] For example, a water level sensor is installed on the driving equipment. The water level sensor can identify the depth of the first driving equipment in the water, thereby determining whether the first driving equipment is at risk of being submerged or whether the first driving equipment has fallen into the water.

[0147] Therefore, based on the external sensing information of the main body of the first driving device, it can be determined whether the first driving device is at risk of being submerged in water or whether the first driving device has fallen into the water.

[0148] By way of example and not limitation, the pose information of the first driving device may include the position information of the first driving device and / or the attitude information of the first driving device.

[0149] For example, the location information of the first driving device can be obtained through its positioning system. For instance, if the positioning system determines that the first driving device is in a lake, the rescue device can determine that the first driving device is at high risk of falling into the water.

[0150] For example, the attitude information of the first driving device can be obtained through its IMU, such as its pitch angle and / or roll angle. The attitude information of the first driving device differs when it is not submerged in water and is operating normally or parked compared to when it is submerged.

[0151] Therefore, based on the position and orientation information of the first driving device, it can be determined whether the first driving device is at risk of being submerged in water or whether the first driving device has fallen into the water.

[0152] As an example and not a limitation, the motion status information of the first driving device may be collected by one or more of wheel speed sensors or millimeter-wave radar.

[0153] For example, wheel speed sensors can detect the motion state of the wheels of the driving equipment, such as wheel speed, whether the wheels are spinning freely, or abnormal situations such as loss of wheel speed sensor signal. The data collected by the wheel speed sensors differs depending on whether the first driving equipment is in normal operation or has fallen into water.

[0154] For example, millimeter-wave radar can detect whether the first driving device experiences an abnormal drop in speed within a short period of time. In the event that the first driving device suddenly falls into the water, its speed may experience an abnormal drop within a short period of time.

[0155] Therefore, based on the motion status information of the first driving device, it can be determined whether the first driving device has fallen into the water.

[0156] As an example and not a limitation, the environmental information within the cockpit of the first driving device can be collected by a humidity sensor within the cockpit (such as the humidity sensor of the air conditioner). In the event that the first driving device is submerged in water or falls into water, the humidity data collected by the humidity sensor will be relatively large.

[0157] Therefore, based on the motion status information of the first driving device, it can be determined whether the first driving device is at risk of being submerged in water or whether the first driving device has fallen into the water.

[0158] As an example and not a limitation, information about occupant behavior may be collected by one or more of the cameras or microphones in the cockpit.

[0159] For example, cameras can detect whether occupants are making escape attempts, such as pulling on door handles, breaking windows, or calling for help.

[0160] For example, microphones can be used to detect whether passengers are calling for help.

[0161] Therefore, based on the occupant's behavioral information, it can be determined whether the first driving device is submerged in water or has fallen into water.

[0162] As an example and not a limitation, occupant physiological information can be collected by millimeter-wave radar within the cockpit (e.g., occupant monitoring system (OMS) millimeter-wave radar). And / or, occupant physiological information can also be obtained from smart wearable devices worn by the occupant.

[0163] For example, OMS millimeter-wave radar can identify information such as the occupant's heart rate and respiratory rate. In the case of drowning, the occupant's heart rate and / or respiratory rate will differ from those in the case of not drowning.

[0164] Therefore, based on the occupants' physiological state information, it can be determined whether the first driving device is at risk of falling into the water.

[0165] S320, based on the first perception data, executes a first rescue strategy, which is one of multiple rescue strategies.

[0166] As described in S310 above, the first perception data includes at least two of the following: environmental information of the first driving device, external perception information of the main body of the first driving device, position and posture information of the first driving device, motion state information of the first driving device, environmental information inside the cockpit of the first driving device, and behavior information of the occupants.

[0167] The rescue device can process and analyze the initial sensing data, determine the appropriate first rescue strategy from multiple preset rescue strategies based on the analysis results, and execute the corresponding rescue strategy.

[0168] By collecting a wealth of sensor data from multiple dimensions and heterogeneous sensors, and analyzing from various perspectives whether the primary driver-in-service device is submerged or has fallen into water, the false alarm rate can be reduced. Determining the appropriate rescue strategy (e.g., the primary rescue strategy) from multiple preset rescue strategies helps improve the success rate of occupant rescue, thereby increasing the occupant survival rate.

[0169] In one possible implementation, based on the first perception data, executing a first rescue strategy includes: determining a first water level of the first driving device from multiple water level classifications based on the first perception data; determining a first rescue strategy corresponding to the first water level from the multiple rescue strategies based on the first water level; and executing the first rescue strategy.

[0170] For example, the rescue device can analyze, based on the first perception data, which of a plurality of preset water level classifications the first driving device conforms to (e.g., the first water level classification). After determining the water level classification of the first driving device, the rescue device can select the rescue strategy corresponding to the first water level classification (e.g., the first rescue strategy) from a plurality of preset rescue strategies and execute the first rescue strategy.

[0171] Optionally, the first water-fall level is determined based on the water-fall score and a first correspondence relationship, which includes multiple sets of water-fall score intervals and water-fall levels. The water-fall score is determined based on the first perception data and is used to indicate the degree of water-fall risk of the first driving device.

[0172] The first correspondence is illustrated below using Table 1 as an example.

[0173] Table 1

[0174]

[0175] As shown in Table 1, the first correspondence can include multiple sets of correspondences between the score intervals and the corresponding relationships. For example, the score interval (0, score 1) corresponds to level 1. The score interval (score 1, score 2) corresponds to level 2. Further examples will not be provided here.

[0176] For example, the rescue device can pre-store a first correspondence. The rescue device can analyze the first sensing data to determine the water score of the first driving device. Therefore, the rescue device can determine which water score range the first driving device falls into; for example, the water score of the first driving device falls into the first water score range. Furthermore, the rescue device can determine the water level corresponding to the first water score range, for example, the first water score level.

[0177] The following combination Figure 4An example is provided to illustrate the calculation of the water score.

[0178] As an example rather than a limitation, the DS evidence theory can be used to calculate the score for falling into the water.

[0179] Taking the first driving device as an example, as mentioned above, the rescue device can acquire first perception data. For example, the first perception data includes environmental information of the first driving device, external perception information of the first driving device, position and posture information of the first driving device, motion status information of the first driving device, environmental information inside the cockpit of the first driving device, and occupant behavior information, etc.

[0180] As an example rather than a limitation, first-sensory data can be divided into four categories.

[0181] The first type can be sensing data used for environmental prediction, including environmental information of the first driving device and the location information of the first driving device. For ease of description, the first type of sensing data is denoted as E1.

[0182] For example, the rescue device can predict whether the first driving device is at risk of falling into the water based on E1. For example, the state space of the judgment can be high risk (represented by H) and low risk (represented by L). For example, if the first driving device is about to enter a dangerous water area, it is considered high risk; if the first driving device is operating normally, it is considered low risk.

[0183] As an example and not a limitation, the BPA based on the E1 environmental risk score can be as shown in Table 2. The values ​​shown in Table 2 are for illustrative purposes only and should not be limiting to the embodiments of this application.

[0184] Table 2

[0185]

[0186] For example, the environmental risk score satisfies the following formula: (For ease of description, this formula will be referred to as Formula 1).

[0187] In Formula 1, F(environment) represents the environmental risk score. F_radar represents the water body identification score obtained based on the sensing data acquired by millimeter-wave radar, F_radar∈[0,1]. F_camera represents the water accumulation / water surface identification score obtained based on the sensing data acquired by a camera, F_camera∈[0,1]. F_gps represents the matching degree of low-lying areas / road deviations obtained based on the positioning system, F_gps∈[0,1]. F_rain represents the normalized value of rainfall intensity obtained based on the sensing data acquired by a rain sensor, F_rain∈[0,1] (for example, moderate rain corresponds to a rainfall intensity of 0.8 or higher).

[0188] Q1, Q2, Q3, and Q4 are weighting coefficients, where Q1 + Q2 + Q3 + Q4 = 1. As an example and not a limitation, Q1 = 0.35, Q2 = 0.3, Q3 = 0.2, and Q4 = 0.15. In practical applications, the values ​​of Q1, Q2, Q3, and Q4 may differ for different models of driving equipment; this embodiment does not impose any limitations on this.

[0189] The second type can be sensing data used to determine whether the first driving device has physically entered the water, including external sensing information of the main body of the first driving device. For ease of description, the second type of sensing data will be denoted as E2.

[0190] For example, the rescue device can determine whether the first driving device has entered the water based on E2. For example, the state space of the determination can be "in water" (represented by W) and "not in water" (represented by D). For example, if the first driving device comes into contact with water, it is considered "in water"; if the first driving device is in a dry state, it is considered "not in water".

[0191] As an example and not a limitation, the BPA based on the E2 ingress confidence score can be as shown in Table 3. The values ​​shown in Table 3 are for illustrative purposes only and should not be limiting to the embodiments of this application.

[0192] Table 3

[0193]

[0194] For example, the confidence score for water entry satisfies the following formula: (For ease of description, this formula will be referred to as Formula 2).

[0195] In Formula 2, C(water entry) represents the water entry confidence score. F_depth represents the score based on the water depth obtained from the water level sensor (or water depth sensor), F_depth ∈ [0, 1]. For example, if the water depth is ≥ 20 cm, the rising rate is > 10 cm / s, and the duration is 1 s, then F_depth = 0.95. F_presure1 represents the score based on the sensing data obtained from the pressure sensor on the door, F_presure1 ∈ [0, 1]. For example, if the pressure is ≥ the pressure threshold and the duration is 1 s, then F_presure1 = 0.9. F_presure2 represents the score based on the sensing data obtained from the pressure sensor on the front bumper, F_presure2 ∈ [0, 1].

[0196] Here, 'a' represents the health coefficient of the water level sensor. 'b' represents the health coefficient of the pressure sensor on the door. 'c' represents the health coefficient of the pressure sensor on the front bumper. The default values ​​for a, b, and c are all 1. If the corresponding sensor malfunctions, its corresponding health coefficient will decrease.

[0197] As an example and not a limitation, the health coefficient can be 0 in cases where the sensor is damaged, the circuit is broken, or the value is abnormal (outside the measurement range). As another example, when the sensor-acquired sensing data fluctuates greatly, the health coefficient can be a smaller value, such as 0.1, 0.2, or 0.3. This application does not limit this to any particular value.

[0198] The third type can be sensing data used to determine whether the first driving device is moving abnormally, including the attitude information and motion state information of the first driving device. For ease of description, the third type of sensing data will be denoted as E3.

[0199] For example, the rescue device can determine whether the first driving device is out of control based on E3. For example, the state space for determination can be out of control (represented by S) and normal (represented by N). For example, if the first driving device has abnormal posture or abnormal movement, it is out of control; if the first driving device has no abnormal posture or movement, it is normal.

[0200] As an example and not a limitation, the BPA based on the runaway confidence score of E3 can be as shown in Table 4. The values ​​shown in Table 4 are for illustrative purposes only and should not be limiting to the embodiments of this application.

[0201] Table 4

[0202]

[0203] For example, the runaway confidence score satisfies the following formula: (For ease of description, this formula will be referred to as Formula 3).

[0204] In Formula 3, I (out of control) represents the out-of-control confidence score. F_IMU represents the attitude anomaly score, F_IMU∈[0,1]. For example, F_IMU=1 when the pitch angle >15° or the roll angle >60°. F_wheel represents the wheel speed anomaly score, F_wheel∈[0,1]. For example, F_wheel=1 when any wheel spins freely or the signal is lost for 0.5s. F_speed represents the speed anomaly score, F_speed∈[0,1]. For example, F_speed=1 when the millimeter-wave radar detects that the speed of the first driving device decreases by >30% within 0.2s (i.e., the speed drops sharply in a short time).

[0205] The fourth type can be perception data used to determine whether the environment inside the cockpit of the first driving equipment is abnormal, including environmental information and occupant behavior information inside the cockpit of the first driving equipment. For ease of description, the fourth type of perception data will be denoted as E4.

[0206] For example, the rescue device can determine whether the environment inside the cabin of the first driving equipment is normal based on E4. For example, the state space of the determination can be abnormal (represented by U) and normal (represented by R). For example, it is considered abnormal if the humidity of the first driving equipment is abnormal, or if the behavior of the occupants is abnormal, or if the physiological state of the occupants is abnormal; it is considered normal if the humidity of the first driving equipment, the behavior of the occupants, and the physiological state of the occupants are all normal.

[0207] As an example and not a limitation, the BPA based on the E4 cabin environment anomaly score can be as shown in Table 5. The values ​​shown in Table 5 are for illustrative purposes only and should not be limiting to the embodiments of this application.

[0208] Table 5

[0209]

[0210] For example, the cabin environment anomaly score satisfies the following formula: (For ease of description, this formula will be referred to as Formula 4).

[0211] In Formula 4, F(cabin) represents the cabin environment anomaly score. F_physiology represents the score of occupant physiological state anomalies based on occupant physiological state information, F_physiology ∈ [0, 1]. For example, if the occupant's heart rate or respiratory rate is 0, F_physiology = 1. F_humidity represents the cabin humidity anomaly score, F_physiology ∈ [0, 1]. F_behavior represents the occupant behavior anomaly score, F_behavior ∈ [0, 1].

[0212] Here, b1 represents the health coefficient of the sensor used to acquire occupant physiological status information. b2 represents the health coefficient of the sensor used to acquire cabin humidity information. B3 represents the health coefficient of the sensor used to acquire occupant behavioral information. The default value for b1, b2, and b3 is 1. If the corresponding sensor malfunctions, the corresponding health coefficient will decrease. For a detailed description, please refer to the detailed description of the sensor health coefficients a, b, and c above; it will not be repeated here.

[0213] The above provides an exemplary illustration of the BPA for each source of evidence (e.g., E1, E2, E3, and E4). The following provides an exemplary illustration of the fusion of these multiple sources of evidence.

[0214] like Figure 4 As shown, E1, E2, E3 and E4 are fused based on the DS evidence theory.

[0215] For the four types of sensory data in this embodiment, any two types of data can be fused first to obtain fusion result 1; then fusion result 1 can be fused with any one of the remaining two types of sensory data to obtain fusion result 2; finally, fusion result 2 can be fused with the remaining type of sensory data to obtain fusion result 3. This fusion result 3 is the final fusion result. In the synthesis rules of the DS evidence theory, the fusion order of multiple types of sensory data does not affect the final fusion result, which is guaranteed by the commutativity and associativity of the DS evidence theory synthesis rules.

[0216] like Figure 4 As shown in this embodiment, E1 and E3 are fused first, then the result of fusing E1 and E3 is fused with E2, and finally the result of fusing E1, E2, and E3 is fused with E4. In practical applications, other fusion orders can also be used, and this embodiment does not limit this.

[0217] In addition, in practical application scenarios, there may be situations where a single sensor or multiple sensors fail. The following is a brief explanation of the possible fault types and corresponding handling strategies in conjunction with Table 6.

[0218] Table 6

[0219]

[0220] like Figure 6 As shown, in the case of a sensor malfunction, the weight coefficient of the evidence source corresponding to that sensor can be reduced to decrease the impact of the sensor's sensing data on the fusion result.

[0221] In cases where the entire source of evidence fails, such as when all sensors associated with the source of evidence malfunction, measures can be taken to skip or discard that source of evidence and fuse only the remaining sources of evidence.

[0222] In the event of a DS calculation timeout, for example, if no fusion result is obtained within a preset calculation cycle, the fusion result of the previous cycle can be used as the fusion result of the current cycle, and the corresponding fault code should be recorded to facilitate subsequent analysis of the cause of the calculation timeout.

[0223] The following example scenario illustrates the fusion process of E1, E2, E3, and E4.

[0224] Example scenario: The first driving device plunges into the river and sinks rapidly. This means that the water level sensor of the first driving device detects a rapid rise in the water level. The pitch angle of the first driving device is 15°, and all the sensors in the cockpit fail.

[0225] Step 1: Input evidence source.

[0226] E1: The millimeter-wave radar detected a body of water, the positioning system detected that the first driving device had deviated from the road, and the rain sensor detected moderate rainfall. In this case, F(environment) = 0.85 is calculated based on the above formula. Based on the BPA corresponding to E1, F(environment) = 0.85 ∈ [0.8, 1], then M1(H) = 0.85, M1(L) = 0.05, M1(θ) = 0.1.

[0227] E2: Water depth > 20cm, water level rise rate 12cm / s, lasting 1s. In this case, C(inflow) = 0.95 is calculated based on Formula 2 above. Based on the BPA corresponding to E2 above, C(inflow) = 0.95 ∈ [0.9, 1], then M2(w) = 0.95, M2(D) = 0.02, M2(θ) = 0.03.

[0228] E3: The pitch angle of the first driving device is 15°, and the duration is 0.5s. In this case, I(out of control) = 0.85 is calculated based on Formula 3 above. Based on the BPA corresponding to E3 above, I(out of control) = 0.85 ∈ [0.8, 1], then M3(S) = 0.9, M3(N) = 0.05, M3(θ) = 0.05.

[0229] E4: The entire source of evidence is invalid; discard the source of evidence.

[0230] Step 2: Fuse E1 and E3 to obtain M13 (including M13(H), M13(L) and M13(θ)).

[0231] Calculate the conflict coefficients of E1 and E3: .

[0232] Calculate M13(H), the probability that the situation is high-risk and out of control: M13(H) = .

[0233] Calculate M13(L), ​​which is the probability of low risk and normalcy (not out of control): M13(L) = .

[0234] Calculate M13(θ): .

[0235] Step 3: Fuse M13 and E2 to obtain M132(H∩S).

[0236] Calculate the conflict coefficients between M13 and E2: .

[0237] Calculate M132(H∩S), which is the probability of high risk + loss of control + already in the water: M132(H∩S) = .

[0238] Since the entire source of evidence E4 is invalid, there is no need to fuse M132(H∩S) with E4. M132(H∩S) can be used as the final score for falling into the water.

[0239] Although the entire E4 evidence source failed, the remaining evidence sources can still be used to determine the circumstances of the first driving device falling into the water, demonstrating good robustness.

[0240] After obtaining the water score, the rescue device can determine the water level of the first driving device based on the water score, and then determine the corresponding rescue strategy.

[0241] In one possible implementation, if the water score is greater than or equal to a first threshold, the first rescue strategy is used to instruct the occupants to wait for rescue in the first driving device; or, if the water score is less than the first threshold but greater than or equal to a second threshold, the first rescue strategy is used to instruct the occupants to escape from the first driving device.

[0242] The first and second thresholds can be preset. The first and second thresholds can be determined based on empirical data, experimental data, or simulation data; this embodiment does not limit this. For example, the first threshold is 0.9, and the second threshold is 0.5.

[0243] For example, if the water depth of the first driving device is greater than or equal to a first threshold, it can be considered that the first driving device has fallen into the water to a relatively high depth. For instance, the main body of the first driving device may be completely submerged in water, and the occupants may not have time or be able to escape successfully on their own. In this case, the first rescue strategy determined by the rescue device can be used to instruct the occupants to wait for external rescue while inside the first driving device.

[0244] If the water depth of the first pilot device is less than the first threshold but greater than or equal to the second threshold, it can be considered that the water depth of the first pilot device is relatively low. For example, the first pilot device has just entered the water, and the water has not yet entered the cabin of the pilot device, so the success rate of the occupants' independent escape is relatively high. In this case, the first rescue strategy determined by the rescue device can be used to instruct the occupants to escape from the first pilot device.

[0245] Optionally, if the number of times the equipment falls into the water is greater than or equal to the first threshold, the first level of falling into the water is level 3. The first rescue strategy corresponding to level 3 includes: controlling the first driving equipment to be in a sealed state; releasing a buoy and sending a first distress signal through the buoy, the first distress signal being used to request rescue of the first driving equipment, the first distress signal including the identification of the first driving equipment and the location information of the first driving equipment; and providing oxygen to the occupants.

[0246] For example, the first threshold is 0.9. If the score for falling into the water is greater than or equal to 0.9, the falling water level is level 3.

[0247] Controlling the first driving device to maintain a sealed state can include ensuring that all doors and windows of the first driving device are closed. For example, if the windows of the first driving device are not fully closed before the water level is determined to be Level 3, the rescue device can raise the windows of the first driving device to a fully closed state after the water level is determined to be Level 3. The rescue device can also control all passages within the cabin that connect to the outside environment (e.g., air conditioning vents) to be closed.

[0248] As an example and not a limitation, the rescue device, while keeping the first driving device in a sealed state, can also prompt the occupants to wait for rescue inside the first driving device.

[0249] For a detailed explanation of the buoy, please refer to the relevant description in the technical terminology section above, which will not be repeated here.

[0250] Providing oxygen to occupants may include: using a rescue device to control the release of the oxygen supply system in the cabin and prompting occupants to wear the oxygen supply system correctly.

[0251] Optionally, the first distress message may also include first information, which may include one or more of the following: the water depth of the first driving device, the attitude of the first driving device, the number of occupants on the first driving device, the location information of the occupants, the physiological state information of the occupants, and the recommended rescue location for rescuing the occupants.

[0252] As an example, and not a limitation, the submersion depth of the first pilot device can be obtained through a water level sensor on that first pilot device. Indicating the submersion depth of the first pilot device via a first distress message helps rescuers understand the urgency of the need for rescue.

[0253] As an example and not a limitation, the attitude of the first driving device can be obtained through its IMU. Indicating the attitude of the first driving device through the first distress message helps the rescuer to take appropriate rescue measures based on the attitude of the first driving device, thereby helping to improve the success rate of the rescue.

[0254] As an example and not a limitation, the number of occupants on the first pilot device can be obtained through millimeter-wave radar and / or cameras within the cockpit of the first pilot device. Indicating the number of occupants on the first pilot device via a first distress message helps rescuers understand the number of occupants awaiting rescue on the first pilot device, thereby enabling them to prepare adequate rescue supplies.

[0255] As an example and not a limitation, the occupant's location information can be obtained through millimeter-wave radar and / or cameras within the cockpit of the first pilot equipment. Not generally, indicating the occupant's location information via a first distress message helps rescuers understand the number of occupants awaiting rescue and their individual locations, thereby enabling them to prepare adequate rescue supplies. Furthermore, based on the location information of each occupant, it helps to shorten rescue time, thus contributing to a higher success rate of rescue.

[0256] As an example, and not a limitation, as mentioned above, the physiological status information of the occupants can be obtained through the OMS millimeter-wave radar in the cockpit of the first pilot equipment. For example, the OMS millimeter-wave radar can identify information such as the occupants' heart rate and respiratory rate. Indicating the physiological status information of the occupants on the first pilot equipment through the first distress message helps the rescuer to determine whether there are still occupants with signs of life on the first pilot equipment.

[0257] As an example, and not a limitation, the recommended rescue location for occupants can be the rescue device, obtained after analyzing the initial perception data. Indicating recommended rescue locations for each occupant through the initial distress message helps provide rescuers with reference information for rescuing the occupants on the primary driving equipment, thereby enabling them to quickly adopt appropriate rescue methods and ultimately improving the rescue success rate.

[0258] Optionally, the rescue strategy corresponding to Level 3 may further include: sending second information to the buoy according to the first cycle, the second information including one or more of the following: the location information of the first driving device, the water depth of the first driving device, the attitude of the first driving device, the physiological state information of the occupant, and the recommended rescue location for rescuing the occupant.

[0259] The first cycle can be preset. The first cycle can be determined based on empirical data, experimental data, or simulation data, and this application embodiment does not limit this.

[0260] As an example and not a limitation, the location information of the first driving device can be obtained through the positioning system of the first driving device. For a detailed description of the water depth of the first driving device, the attitude of the first driving device, the physiological state information of the occupant, and the recommended rescue location for the occupant, please refer to the relevant description of the first information above, which will not be repeated here.

[0261] The rescue device periodically sends a second message to the buoy, which helps the buoy update the relevant information in the first distress message based on the latest information of the first driving equipment. This helps rescuers such as the rescue center to obtain the latest information of the first driving equipment, so as to adjust the rescue plan in a timely manner and take more appropriate rescue methods.

[0262] Optionally, if the water score is less than the first threshold and greater than or equal to the third threshold, the first water score is level 2. The first rescue strategy corresponding to level 2 includes: controlling all door locks of the first driving device to be unlocked; controlling the window of the first driving device to be lowered to the lowest height supported by the window; sending a second distress message, which requests rescue for the first driving device, and the second distress message includes the identifier of the first driving device and the location information of the first driving device; wherein the third threshold is greater than the second threshold and less than the first threshold.

[0263] The third threshold can be preset. The third threshold can be determined based on empirical data, experimental data, or simulation data; this application embodiment does not limit this.

[0264] Level 2 is lower than Level 3. For example, the third threshold is 0.7. A fall-over score of less than 0.9 and greater than or equal to 0.7 is classified as Level 2.

[0265] For example, in the case where the water level of the first driving device is level 2, the body of the first driving device has not been completely submerged in water, and the occupants of the first driving device still have time and opportunity to escape on their own.

[0266] For example, if the water immersion level of the first driving device is determined to be Level 2, the rescue device can control all the door locks of the first driving device to be unlocked and control the windows of the first driving device to lower to the lowest height supported by the windows, thereby helping the occupants of the first driving device to quickly and independently escape from the first driving device. By way of example and not limitation, the rescue device can also indicate to the occupants that the door locks and windows are open and to escape from the first driving device as soon as possible.

[0267] Taking into account the need to salvage the first driving equipment and the presence of occupants who did not voluntarily escape from it, the rescue device can also send a second distress signal to request rescue of the first driving equipment.

[0268] Optionally, the second distress message may also include first information, which includes one or more of the following: the water depth of the first driving device, the attitude of the first driving device, the number of occupants on the first driving device, the location information of the occupants, the physiological state information of the occupants, and a recommended rescue location for rescuing the occupants. For a detailed description, please refer to the description of the first information above, which will not be repeated here.

[0269] Optionally, if the water score is less than the third threshold and greater than or equal to the second threshold, the first water level is level 1. The first rescue strategy corresponding to level 1 includes: outputting a first alarm message, which is used to indicate that the first driving device has a risk of water immersion; wherein the third threshold is greater than the second threshold and the third threshold is less than the first threshold.

[0270] Level 1 is lower than Level 2. A falling water score of less than 0.7 and greater than or equal to 0.5 is classified as Level 1.

[0271] For example, if the water level of the first driving device is Level 1, it can be assumed that the first driving device will be passing through puddles or low-lying areas with deep water, which may pose a risk of water immersion, but is not enough to threaten the lives of the occupants of the first driving device. In this case, the rescue device can output a first warning message to alert the user that the first driving device is at risk of water immersion.

[0272] As an example and not a limitation, in real-world applications, the rescue device may output the first alarm message through sound (including voice) and / or light.

[0273] Optionally, the rescue strategy corresponding to Level 1 may also include: controlling the drive motor of the first driving device to stop working; and / or controlling the window of the first driving device to drop a first height (e.g., 5 cm).

[0274] For example, stopping the drive motor of the first driving device can be understood as cutting off the power to the first driving device. Cutting off the power to the first driving device in time before it enters a puddle or a low-lying area with standing water helps to prevent the risk of the first driving device being submerged (or wading) due to entering the standing water.

[0275] The window of the first driving device is lowered to a first height so that the occupants of the first driving device can observe the environment of the first driving device through the open window gap, which helps to reduce the risk of the first driving device driving into the water and wading through the water.

[0276] In one possible implementation, multiple preset rescue strategies can also be associated with the health status of the first power module of the first driving device. This first power module supplies power to the drive motor of the first driving device. In practical applications, some driving devices' first power modules, in addition to supplying power to the drive motor and providing power for the device's movement, can also supply power to the device's high-voltage electrical system.

[0277] For example, if necessary, the rescue device can promptly de-energize the first power module, reducing the risk of electric shock to occupants due to short circuits caused by water immersion.

[0278] Optionally, the method 300 further includes: detecting the health status of the first power module when the risk of the first driving device falling into the water is determined to be greater than or equal to a fourth threshold based on the environmental information, and / or when the probability of the first driving device malfunctioning is determined to be greater than or equal to a fifth threshold based on the pose information and the motion state information.

[0279] The fourth and fifth thresholds can be preset. The fourth and fifth thresholds can be determined based on empirical data, experimental data, or simulation data; this application does not limit this.

[0280] For example, as described above, the rescue device can obtain environmental information about the first driving device. The rescue device can analyze the environmental information about the first driving device, and if it determines that the risk of the first driving device falling into the water is greater than or equal to a fourth threshold, the rescue device can initiate a health status check on the first power module.

[0281] As mentioned above, the rescue device can acquire the attitude and motion status information of the first driving device. The rescue device can analyze the attitude and motion status information of the first driving device, and if it determines that the probability of the first driving device malfunctioning is greater than or equal to the fifth threshold, the rescue device can initiate a health status check on the first power module.

[0282] Without loss of generality, in practical application scenarios, if the risk of the first driving device falling into the water is determined to be greater than or equal to the fourth threshold based on the environmental information, and the probability of the first driving device malfunctioning is determined to be greater than or equal to the fifth threshold based on the attitude information and the motion state information, the rescue device can activate the detection of the health status of the first power module.

[0283] The following combination Figure 5 An exemplary description is provided of the process for detecting the health status of the first power module.

[0284] Figure 5 The steps shown for detecting the health status of the first power module can be controlled and executed by the rescue device.

[0285] S501, inject sweep frequency signal.

[0286] For example, before obtaining the water immersion rating of the first driving device, if it is necessary to check the health status of the first power module, the rescue device can control the battery management system (BMS) to inject a sweep frequency signal into the circuit connected to the first power module. For ease of description, the circuit connected to the first power module is referred to as the high-voltage circuit.

[0287] By way of example and not limitation, the sweep signal can be a small voltage signal with a frequency that varies continuously from 1 kilohertz (kHz) to 100 kHz. When injecting this sweep signal, its amplitude can be controlled within a sixth threshold. This sixth threshold needs to be much lower than the amplitude of the high-voltage bus connected to the first power module (e.g., 400 volts (V) or 800V) so as not to affect the normal power supply of the first power module to the high-voltage circuit. For example, the sixth threshold is 5V.

[0288] S502, acquires response signals.

[0289] The response signal can be a current signal. This current signal can also be called the response current, and this application does not limit it in this respect.

[0290] For example, the rescue device can control the BMS to collect the response current on the high-voltage circuit near the injection point of the sweep frequency signal.

[0291] S503, Impedance Spectroscopy Analysis.

[0292] For example, the BMS may pre-store the health baseline of the first power module. By way of example and not limitation, the impedance spectrum of the first power module measured at various temperatures when the first driving device leaves the factory may be used as the health baseline of the first power module.

[0293] After receiving the response current, the rescue device can control the BMS to calculate the impedance modulus values ​​under multiple sweep frequency signal frequency bands.

[0294] For example, the impedance magnitude satisfies the following formula: (For ease of description, this formula is referred to as Formula 5). Wherein, |Z| represents the impedance magnitude, "V_input" represents the sweep frequency signal, and "I_response" represents the response current.

[0295] The rescue device can control the BMS to calculate the phase difference (i.e., the difference in phase angle between the sweep signal voltage and the response current) under multiple sweep signal frequency bands. This phase difference can be used to analyze the health status of the first power supply module. A detailed description can be found in Table 7 below, and will not be elaborated upon here.

[0296] As an example rather than a limitation, the frequency range of a swept signal can be divided into a low frequency range (e.g., 1kHz to 10kHz), a mid frequency range (e.g., 10kHz to 50kHz), and a high frequency range (e.g., 50kHz to 100kHz).

[0297] After calculating the impedance magnitude of the first power module at various frequency bands, the impedance spectrum for each frequency band can be obtained based on these impedance magnitudes. The rescue device can control the BMS to compare the impedance spectrum at each frequency band with a pre-stored health baseline. Furthermore, the health status of the first power module can be calculated.

[0298] As an example and not a limitation, the health of the first power module satisfies the following formula: (For ease of description, this formula is referred to as Formula Six.) Where H represents the health status of the first power module, and a is a sensitivity coefficient, representing the sensitivity of the function detecting the health status of the first power module to the Pukang deviation. Indicates the magnitude of the impedance deviation. , This represents the measured and calculated impedance magnitude of the first power supply module. This represents the impedance magnitude corresponding to the pre-stored impedance spectrum.

[0299] In practical applications, the sensitivity coefficient 'a' can be pre-calibrated. Optionally, the sensitivity coefficient 'a' can also be dynamically adjusted. For example, it can be adaptively adjusted based on the usage time of the driving device. This application does not limit this aspect.

[0300] For example, if H ≥ 0.9, the BMS can determine that the first power module is in a healthy state. If H < 0.9, the BMS can determine that the first power module is in an unhealthy state.

[0301] As an example and not a limitation, when the first power module is in a healthy state, the BMS can detect the health status of the first power module at a normal detection cycle (e.g., 100 milliseconds).

[0302] As an example rather than a limitation, unhealthy states can also include attention states, warning states, and dangerous states.

[0303] For example, when 0.9 > H ≥ 0.7, the BMS determines that the first power module is in a state of alert. When the first power module is in a state of alert, the BMS can output an alarm message to indicate that the health of the first power module needs to be monitored, and perform health checks on the first power module at a shorter interval than the normal detection cycle, that is, increase the detection density of the health status of the first power module (which can be referred to as encrypted detection).

[0304] For example, if 0.7 > H ≥ 0.5, the BMS determines that the first power module is in a warning state. When the first power module is in a warning state, the BMS can output a warning message to indicate that the health of the first power module needs to be taken seriously, restrict charging of the first power module, and prepare to control the first power module to shut down.

[0305] For example, if H < 0.5, the BMS determines that the first power module is in a dangerous state. In the event that the first power module is in a dangerous state, the BMS can immediately control the first power module to shut down.

[0306] As an example and not a limitation, the BMS can control the first power module to power down according to a pre-set power-down sequence. For example, the main relay is disconnected at T1ms; active discharge is performed at T2ms; and interlock confirmation is performed at T3ms.

[0307] In extreme situations such as the driving equipment falling into the water, the core objective of controlling the high voltage of the first power module is to find a balance between preventing electric shock to the occupants and preserving the power supply for escape.

[0308] In the event that the driving equipment falls into the water, the capacitor on the DC bus in the high-voltage circuit of the first power module still retains a large amount of charge. If the relay is simply disconnected, a relatively high voltage will remain on the high-voltage side.

[0309] As an example rather than a limitation, the high-voltage power-on timing is 0ms to 500ms.

[0310] Phase 1: T1=0ms, perform physical isolation and disconnect the main relay. For example, disconnect the main positive relay and / or the main negative relay.

[0311] For example, the BMS can send a hard-wired pulse width modulation (PWM) disconnect signal to the main positive and / or main negative relays. At this time, the high-voltage bus of the first power module is physically disconnected, and the first power module no longer outputs current. The voltage across the bus capacitor of the first power module remains at approximately 400V / 800V, and high-voltage loads such as the drive motor controller and air conditioning compressor remain energized.

[0312] Phase 2: T2_1 = 50ms, active discharge activation.

[0313] Immediately close the active discharge circuit, such as by connecting a discharge resistor with a resistance of approximately 100-200 ohms (Ω).

[0314] Phase 3: T2_2=250ms, high voltage is released to the safe threshold.

[0315] The BMS samples the bus voltage to determine if it has dropped to a safe threshold. For example, the safe threshold is below 60V.

[0316] Phase 4: T3=500ms, high-voltage interlock and insulation confirmation.

[0317] The BMS reads the interlock circuit status of all high-voltage connectors to confirm that no high-voltage plugs have become energized and dislodged in the water.

[0318] Insulation monitoring: Inject high-frequency impedance spectrum and remeasure the current insulation resistance value.

[0319] After completing high-voltage interlock and insulation verification, a high-voltage safety status flag can be set, unlocking escape permissions. For example, the BMS can send a signal indicating "high-voltage safety status" to the driver's control area network (CAN) bus. In Zhehong's case, the rescue device can control the emergency power supply to power the window drive motor, controlling the window to lower.

[0320] Additionally, the rescue device can determine whether there is a potential difference between the cockpit and the high-voltage components. If there is no potential difference between the cockpit and the high-voltage components, even if water floods into the cockpit, the occupants will not form a conductive circuit in their limbs if they open the door.

[0321] As an example, and not a limitation, if the backup emergency power supply is severely insufficient, the high-voltage power-down sequence can be adjusted, and degraded logic can be implemented. For example, the principle of this adjustment could be: escape priority > high-voltage discharge.

[0322] For example, the degradation logic is:

[0323] 1) If the emergency power supply is detected to be below 30% at T1=0ms, the rescue device can cancel the forced active discharge, temporarily suspend the energy consumption through the resistor, and reserve the limited power for the peak current of the window motor.

[0324] 2) The high-voltage end slowly returns to zero through physical isolation (relay disconnection) and passive discharge (resistor self-heating). This helps occupants to lower the windows and escape as soon as possible.

[0325] Optionally, when 0.9 > H ≥ 0.7, the rescue device can control the BMS to analyze the type of failure of the first power module.

[0326] For example, the BMS can analyze the impedance spectrum at each frequency band obtained by measurement and calculation with a pre-stored health baseline to determine the fault type of the first power supply module. This is illustrated below with reference to Table 7.

[0327] Table 7

[0328]

[0329] In particular, not only in the high frequency range, but in any frequency range, if the impedance magnitude of the first power supply module drops sharply, it can be determined that the fault category of the first power supply module is that there is a risk of short circuit.

[0330] As shown in Table 7, if the impedance spectrum of the first power supply module corresponds to the characteristics of the unhealthy state in Table 7, the BMS can determine that the first power supply module has experienced a fault of the corresponding type.

[0331] Optionally, if the first water level is level 2 or level 3, and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: controlling the first power module to power off and controlling the second power module of the first driving device to power on; wherein the second power module is used to supply power to the first driving device in the event that the first power module malfunctions or is in an abnormal state.

[0332] The second power module can be a backup power module or an emergency power module of the first driving device. The output voltage of the second power module is lower than the output voltage of the first power module.

[0333] For example, the rescue strategy corresponding to Level 2 or Level 3 further includes: if the health status of the first power module is unhealthy, controlling the first power module to power down and controlling the second power module to power the first driving device. For example, the second power module can power the oxygen supply device on the first driving device.

[0334] As an example, and not a limitation, in the event that the first power module is in a dangerous state, the rescue device controls the first power module to perform voltage reduction according to a preset power-down sequence. For a detailed description, please refer to the above. Figure 5 The relevant descriptions will not be repeated here.

[0335] Optionally, if the first water level is level 1 and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: outputting a second alarm message, which is used to indicate that the first power module is in an unhealthy state.

[0336] For example, the rescue strategy corresponding to Level 1 further includes: when the health status of the first power module is unhealthy, outputting a second alarm message to prompt the occupants to pay attention to the health status of the first power module.

[0337] In one possible implementation, the preset rescue strategies can also be linked to the occupants' physiological state information. For example, the preset rescue strategies can be dynamically adjusted based on the occupants' physiological state information. The following combines... Figure 6 This needs to be explained.

[0338] like Figure 6 As shown, the rescue device can obtain the occupant's physiological status information through sensors on the first driving device. For example, as mentioned above, the OMS millimeter-wave radar can identify information such as the occupant's heart rate and respiratory rate.

[0339] In addition, in real-world scenarios, the camera inside the cockpit of the first driving device can identify the occupant's posture (such as sitting upright, leaning forward, or reclining) and head position.

[0340] The gravity sensor on the seat can also identify the gravity distribution on the seat, thereby determining whether the seat is occupied and the status of the occupant's departure.

[0341] Furthermore, the camera inside the cockpit of the first driving device can identify whether the occupant's eyes are open or closed, and whether the occupant has any active escape behavior or intention, such as calling for help, actively triggering the rescue alarm, pulling on the door handle, or knocking on the window.

[0342] Based on the perception data obtained from one or more of the millimeter-wave radar, cameras, or gravity sensors on the seats in the cockpit of the first driving device, the state category of each occupant can be determined.

[0343] As examples, and not limitations, if an occupant's respiratory rate is 12-20 breaths per minute, their eyes are open, eye movements are present, and the occupant shows an attempt to escape (or engage in an escape attempt), the occupant's state category is conscious and active. If an occupant's respiratory rate is 12-20 breaths per minute, their eyes are open, eye movements are present, but the occupant shows no attempt to escape (or engage in an escape attempt), the occupant's state category is conscious and passive. If an occupant's respiratory rate is 10-15 breaths per minute, their eyes are closed, and they show no attempt to escape (or engage in an escape attempt), the occupant's state category is asleep. If an occupant's respiratory rate is <8 breaths per minute, their eyes are closed, and they show no attempt to escape (or engage in an escape attempt), the occupant's state category is comatose. If an occupant shows no respiratory signal, the occupant's state category is asymptomatic.

[0344] Optionally, the rescue strategy corresponding to Level 2 can be adaptively adjusted based on the physiological status information of each occupant.

[0345] For example, if the first driving device is classified as Level 2 in terms of water immersion level, for occupants in a conscious and active state, the rescue device can lower the window on the occupant's side to the lowest height it supports and unlock the door on that side. Optionally, for occupants in a conscious and active state, the rescue device can supply oxygen to them at a basic flow rate (e.g., 5 liters (L) / min).

[0346] For example, if the first driving device is classified as Level 2 in terms of water immersion, for occupants in a conscious but passive state, the rescue device can provide voice prompts to the occupant to unfasten their seatbelt and prepare to escape. It can also lower the window on the occupant's side to the lowest possible height and unlock the door on that side. Optionally, for occupants in a conscious but passive state, the rescue device can supply oxygen to them at a basic flow rate.

[0347] For example, if the first driving device is classified as Level 2 in terms of water immersion level, for occupants in a sleep state, the rescue device can wake them up through seat vibration and / or voice commands. If the occupant is awakened within a preset first duration (e.g., 3 seconds), their state category can be switched to an awake passive state. If the occupant is not awakened within the preset first duration, their state category can be switched to a comatose state.

[0348] For example, if the first control device is classified as having a Class 2 water level fall, and the occupant is unconscious, the rescue device can control the oxygen supply system to provide oxygen at a higher flow rate (e.g., 12 L / min). Optionally, for an occupant who is unconscious, the rescue device can direct the oxygen supply system's directional nozzle towards the occupant's mouth and nose. Optionally, if the first control device is classified as having a Class 2 water level fall and there is an unconscious occupant on the first control device, the rescue device can also control the release of a buoy and issue an alarm message via sound and / or lights.

[0349] For example, if the first driving device is classified as Level 2 in terms of water immersion level, the rescue device can control the oxygen supply device to stop supplying oxygen to the occupant who is in a state of no vital signs.

[0350] In one possible implementation, the rescue device can also calculate a feasibility score for each occupant to pass through each escape exit based on the attitude of the first driving device and the occupant's position information. As an example, and not a limitation, one door represents one escape exit.

[0351] As an example, and not a limitation, the feasibility score of an escape route satisfies the following formula: (For ease of description, this formula will be referred to as Formula Seven). Wherein, P_wd represents the feasibility score of occupant pa_1 escaping through escape exit ex_1; P_s represents the probability that escape exit ex_1 can be opened; and D_a represents the proximity of occupant pa_1 to escape exit ex_1. P_wd, P_s, and D_a are rational numbers between 0 and 1. u1, u2, and u3 are weighting coefficients, where u1 + u2 + u3 = 1.

[0352] For example, the rescue device can calculate P_wd using data collected by pressure sensors on the vehicle doors. The rescue device can obtain P_s based on the attitude of the first driving device. The rescue device can obtain D_a based on the distance of occupant pa_1 from each escape exit.

[0353] After calculating the feasibility score of occupant pa_1 escaping from each escape exit, the rescue device can use the escape exit with the highest feasibility score as the recommended exit (or location) for occupant pa_1 to escape or the recommended exit (or location) for rescuing occupant pa_1.

[0354] As an example, and not a limitation, if the first control unit is in a Class 2 water-related accident, the rescue device could provide voice prompts to each occupant recommending an escape route. As another example, if the first control unit is in a Class 3 water-related accident, the rescue device could send recommended rescue locations to buoys, which could then indicate the recommended rescue locations based on the initial distress message.

[0355] In one possible implementation, the submerged driving equipment can communicate underwater, establishing an underwater acoustic link network, thereby enabling coordinated rescue operations based on this network. The following combines... Figure 7 This will be illustrated by example.

[0356] like Figure 7 As shown, the driving equipment that has fallen into the water can communicate with each other using underwater acoustic communication technology.

[0357] Underwater acoustic communication is a technology that uses sound waves to propagate in water for information transmission. Sound waves are the only physical medium capable of long-distance propagation in water. Similar to how submarines communicate using sonar, underwater navigation equipment can also communicate with each other using underwater sound.

[0358] For example, after the driving equipment falls into the water, the rescue device can control the release of a buoy. The buoy can convert electrical signals into sound wave signals and transmit them. For a detailed description of the buoy, please refer to the explanation of technical terminology above, which will not be repeated here.

[0359] For example, a buoy can send a first distress signal. A detailed description of the first distress signal can be found in the relevant explanation above, and will not be repeated here.

[0360] The information encoding of the initial distress message can be transmitted via sound waves of a specific frequency. The sound waves carrying the initial distress message can propagate in all directions in the form of spherical waves.

[0361] After the buoy of the first control device emits a sound wave carrying the first distress message, the buoys of other control devices that have fallen into the water can receive the sound wave and decode the first distress message.

[0362] Other submerged driving devices can calculate the distance between themselves and the first driving device by calculating the time difference between the arrival time and the transmission time of the sound wave.

[0363] Optionally, the rescue strategy corresponding to Level 3 further includes: sending a third distress message to the second driving device, the third distress message including the identifier and location information of the first driving device, the third distress message being used to request rescue of the first driving device. Optionally, the third distress message also includes first information. A detailed description of the first information can be found in the relevant description above, and will not be repeated here.

[0364] For example, such as Figure 7 As shown, the submerged driving equipment communicates with each other using underwater acoustic communication technology, forming an underwater acoustic link network. Driving equipment within the same underwater acoustic link network can communicate with each other.

[0365] For example, driving devices A, B, C, and D form an underwater acoustic link network. Taking driving device A as an example of the first driving device, driving device A can send a third distress message to a second driving device, which can be one or more of driving devices B, C, and D.

[0366] Optionally, the rescue strategy corresponding to Level 3 further includes: obtaining a fourth distress signal from the third driving device, the fourth distress signal including the identifier and location information of the third driving device, the fourth distress signal being used to request rescue of the third driving device; and sending the fourth distress signal to the buoy. Optionally, the fourth distress signal also includes first information. A detailed description of the first information can be found in the relevant description above, and will not be repeated here.

[0367] like Figure 7 As shown, driving device A is used as an example of a first driving device. Driving device A can obtain a fourth distress message from a third driving device, which can be one or more of driving devices B, C, and D.

[0368] like Figure 7 As shown, in practical applications, driving devices within the same underwater acoustic link network can communicate distress signals. Thus, once the buoy of one driving device (e.g., the buoy of driving device A) successfully surfaces, that buoy can act as the master node in the network, transmitting distress signals from all driving devices within the network. For example, the buoy can send distress signals from the driving devices in the network to a rescue center.

[0369] Optionally, after the first driving device obtains the request information of at least one other driving device that has fallen into the water, the rescue device of the first driving device can prioritize the rescue of the first driving device and the at least one other driving device that has fallen into the water based on the distress information of the first driving device and the request information of the at least one other driving device that has fallen into the water, and can send out the rescue priority ranking result through a buoy.

[0370] As an example and not a limitation, the rescue device of the first driving device can calculate the rescue priority score corresponding to each driving device that has fallen into the water based on the distress information obtained from each driving device that has fallen into the water, and then sort the multiple driving devices that have fallen into the water by rescue priority based on the rescue priority score of each driving device.

[0371] For example, the rescue priority score for a submerged vehicle satisfies the following formula: F = w1 × F_wd + w2 × F_ns + w3 × F_p + w4 × F_t (for ease of description, this formula is referred to as Formula Eight). Where F represents the rescue priority score for the vehicle; F_wd represents the score for the depth of the vehicle submerged in water; F_ns represents the score for the number of survivors on the vehicle; F_p represents the score for the posture of the vehicle; and F_t represents the score for the duration of the vehicle's submersion in water. F_wd, F_ns, F_p, and F_t are rational numbers between 0 and 1. w1, w2, w3, and w4 are weighting coefficients, and w1 + w2 + w3 + w4 = 1.

[0372] The fraction of the driving equipment's submersion depth is negatively correlated with the actual submersion depth of the driving equipment. That is, the smaller the submersion depth of the driving equipment, the larger its fraction of submersion depth; conversely, the larger the submersion depth of the driving equipment, the smaller its fraction of submersion depth.

[0373] The score for the number of survivors on a driving device is positively correlated with the number of survivors on that driving device. That is, the more survivors on a driving device, the higher the score for the number of survivors on that driving device; the fewer survivors on a driving device, the lower the score for the number of survivors on that driving device.

[0374] The attitude score of the driving equipment is negatively correlated with the roll angle and / or pitch angle of the driving equipment. That is, the larger the roll angle and / or pitch angle of the driving equipment, the smaller the attitude score of the driving equipment; the smaller the roll angle and / or pitch angle of the driving equipment, the higher the attitude score of the driving equipment.

[0375] The score for the duration of the driving equipment's submersion in water is negatively correlated with the duration of the submersion. That is, the longer the submersion time of the driving equipment, the smaller the score for that duration; the shorter the submersion time of the driving equipment, the larger the score for that duration.

[0376] Optionally, the method 300 further includes: sending the first sensing data to a cloud server. A detailed description of the first sensing data can be found in the relevant explanation above, and will not be repeated here.

[0377] For example, such as Figure 8 As shown, each driving device can correspond to an independent digital twin in the cloud. The digital twin can run two engines: a standard engine and an aggressive engine. The rescue method logic and parameter thresholds run by the standard engine are exactly the same as those run by the physical driving device. The rescue method logic run by the aggressive engine is the same as that run by the physical driving device, but the parameter thresholds are different. For example, the parameter thresholds on the aggressive engine are reduced by 20% compared to the standard engine (e.g., a water depth threshold of 16cm and an attitude threshold of 12°) to detect potential missed detections.

[0378] Taking the first driving device as an example, after acquiring the first perception data, the first driving device can send the first perception data to the cloud server.

[0379] After obtaining the first perception data from the first driving device, the cloud server can process and analyze the first perception data based on the standard engine and the radical engine respectively, and can perform difference analysis on the output results of the standard engine and the radical engine.

[0380] For example, if the aggressive engine determines that the first driver unit has fallen into the water (confidence level > 0.7), while the standard engine does not, a missed detection warning can be triggered, and data packets for the preceding and following 10 seconds can be recorded. As another example, if the first driver unit initiates a rescue response, but the aggressive engine does not determine that the first driver unit has fallen into the water, a false detection warning can be triggered, and data for the preceding and following 10 seconds can be recorded.

[0381] The cloud server can store all warning data related to the first-hand driving device in a labeled library for subsequent model training and iterative updates. For example, the cloud server can periodically perform offline backtracking on historical data in the labeled library. For example, the cloud server can use Bayesian optimization to search for the optimal combination of thresholds, minimizing the false negative and false positive rates. The cloud server can also distribute the optimized parameter thresholds to the first-hand driving device via OTA, achieving closed-loop evolution of the rescue method model.

[0382] Based on the aforementioned method 300, firstly, by analyzing at least two of the following: environmental information of the driving equipment, external sensory information of the driving equipment, posture information of the driving equipment, motion state information of the driving equipment, environmental information inside the driving equipment cabin, and occupant behavior information, a suitable rescue strategy is determined from multiple rescue strategies. This helps to obtain the true situation of the driving equipment falling into the water, reduces the misjudgment rate, and thus helps to determine a suitable rescue strategy from multiple preset rescue strategies, thereby improving the occupant survival rate.

[0383] In addition, the introduction of high-voltage safety linkage, through impedance spectrum analysis of the first power module, monitors the health of the high-voltage circuit in real time, integrates the control logic of the first power module with the rescue strategy, detects the health of the first power module before determining the level of submersion, and provides proactive warnings, which helps to reduce the risk of electric shock to occupants due to short circuits in the high-voltage circuit of the first power module.

[0384] Furthermore, by combining the physiological state of the occupants and making adaptive adjustments to the rescue strategy for each occupant, it is possible to carry out appropriate rescue measures for each occupant in a targeted manner, thereby helping to improve the occupant's escape rate and survival rate.

[0385] Furthermore, multiple submerged vehicles can form an underwater acoustic link network using underwater acoustic communication, coordinating with each other and exchanging their distress signals. As long as at least one vehicle's buoy successfully surfaces, it can transmit the distress signals of all vehicles in the network. This helps ensure that every vehicle in the network can be rescued.

[0386] The rescue method provided in the embodiments of this application has been described in detail above. The rescue device provided in the embodiments of this application will be described exemplarily below with reference to the accompanying drawings.

[0387] Figure 9 This is a schematic structural diagram of the rescue device provided in the embodiments of this application.

[0388] Rescue devices applicable to the rescue methods provided in the embodiments of this application, such as Figure 9 The rescue device 900 shown may include a multi-source heterogeneous perception layer, a fusion decision layer, a decision and response layer, an execution layer, and a support layer.

[0389] The multi-source heterogeneous sensing layer can be used to acquire the first sensing data. A detailed description of the first sensing data can be found in the relevant description in method 300 above, and will not be repeated here. The multi-source heterogeneous sensing layer may include... Figure 1 The sensing system 110 shown or Figure 2 The sensing module 210 shown may contain one or more sensors, but this application embodiment does not limit the specific sensors used.

[0390] The fusion decision layer can be used to process and analyze the initial perception data to obtain the water penetration score. For example, it can calculate the water penetration score of a driving device based on the DS evidence theory. The fusion decision layer may include, for example... Figure 1 One or more processors in the computing platform 120 shown. This application embodiment does not limit this.

[0391] The decision and response layer can be used to determine the water level based on the water score obtained from the fusion decision layer. For example, if the water score is greater than or equal to 0.9, the water level of the driving equipment is level 3, and the rescue device can initiate a level 3 response. If the water score is less than 0.9 but greater than or equal to 0.7, the water level of the driving equipment is level 2, and the rescue device can initiate a level 2 response. If the water score is less than 0.7 but greater than or equal to 0.5, the water level of the driving equipment is level 1, and the rescue device can initiate a level 1 response. If the water score is less than 0.5, it is determined that the driving equipment has not fallen into the water, and the rescue device may not initiate a rescue response. The decision and response layer may also include, for example, […]. Figure 1 One or more processors in the computing platform 120 shown. This application embodiment does not limit this.

[0392] The execution layer can be used to execute the rescue strategy corresponding to the water level determined by the decision and response layer. For a detailed description of the rescue strategy corresponding to each water level, please refer to the relevant description in method 300 above, which will not be repeated here.

[0393] The support layer can be used to include modules that support one or more of the following capabilities: adjustment of adaptive rescue measures based on occupant physiological status information, coordinated rescue through underwater acoustic link networking between submerged driving equipment, fusion of the health status of the first power module and rescue strategy, and operation of the digital twin, etc. Detailed descriptions of the above capabilities can be found in the relevant descriptions in Method 300 above, and will not be repeated here.

[0394] Figure 10 This is another schematic block diagram of the rescue device provided in the embodiments of this application.

[0395] like Figure 10 As shown, the rescue device 1000 includes an acquisition module 1010 and a processing module 1020.

[0396] For example, when the rescue device 1000 is used to implement the function of the rescue device in any embodiment of the method 300 described above, the acquisition module 910 can be used to: acquire first perception data, which includes at least two of the following information: environmental information of the first driving device, external perception information of the main body of the first driving device, position and posture information of the first driving device, motion state information of the first driving device, environmental information inside the cabin of the first driving device, occupant behavior information, and occupant physiological state information; the processing module 1020 can be used to: execute a first rescue strategy based on the first perception data, which is one of multiple rescue strategies.

[0397] Optionally, the processing module 1020 may be specifically used to: determine the first water level of the first driving device from multiple water level classifications based on the first perception data; determine the first rescue strategy corresponding to the first water level from multiple rescue strategies based on the first water level; and execute the first rescue strategy.

[0398] Optionally, the first water-fall level is determined based on the water-fall score and a first correspondence relationship, which includes multiple sets of water-fall score intervals and water-fall levels. The water-fall score is determined based on the first perception data and is used to indicate the degree of water-fall risk of the first driving device.

[0399] Optionally, if the water score is greater than or equal to a first threshold, the first rescue strategy is used to instruct the occupant to wait for rescue in the first driving device; or, if the water score is less than the first threshold but greater than or equal to a second threshold, the first rescue strategy is used to instruct the occupant to escape from the first driving device.

[0400] Optionally, if the water score is greater than or equal to the first threshold, the first water level is level 3, and the first rescue strategy corresponding to level 3 includes: controlling the first driving device to be in a sealed state; releasing a buoy and sending a first distress signal through the buoy, the first distress signal being used to request rescue of the first driving device, the first distress signal including the identifier of the first driving device and the location information of the first driving device; and providing oxygen to the occupant.

[0401] Optionally, if the water score is less than the first threshold and greater than or equal to the third threshold, the first water level is level 2. The first rescue strategy corresponding to level 2 includes: controlling all door locks of the first driving device to be unlocked; controlling the window of the first driving device to be lowered to the lowest height supported by the window; sending a second distress message, which requests rescue for the first driving device, and the second distress message includes the identifier of the first driving device and the location information of the first driving device; wherein the third threshold is greater than the second threshold and the third threshold is less than the first threshold.

[0402] Optionally, if the water score is less than the third threshold and greater than or equal to the second threshold, the first water level is level 1, and the first rescue strategy corresponding to level 1 includes: outputting a first alarm message, which is used to indicate that the first driving device has a risk of water immersion; wherein the third threshold is greater than the second threshold and the third threshold is less than the first threshold.

[0403] Optionally, the first distress message may also include first information, which may include one or more of the following: the water depth of the first driving device, the attitude of the first driving device, the number of occupants on the first driving device, the location information of the occupants, the physiological state information of the occupants, and a recommended rescue location for rescuing the occupants.

[0404] Optionally, the first rescue strategy corresponding to level 3 further includes: sending second information to the buoy according to a first cycle, the second information including one or more of the following: the location information of the first driving device, the water depth of the first driving device, the attitude of the first driving device, the physiological state information of the occupant, and the recommended rescue location for rescuing the occupant.

[0405] Optionally, if the first water level is level 2 or level 3, and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: controlling the first power module to power off and controlling the second power module of the first driving device to power on; wherein the first power module is used to supply power to the drive motor of the first driving device, and the second power module is used to supply power to the first driving device in the event that the first power module malfunctions or is in an abnormal state.

[0406] Optionally, if the first water level is level 1 and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: outputting a second alarm message, which is used to indicate that the first power module is in an unhealthy state; wherein the first power module is used to supply power to the drive motor of the first driving device.

[0407] Optionally, the processing module 1020 can also be used to: detect the health status of the first power module when the risk of the first driving device falling into the water is determined to be greater than or equal to a fourth threshold based on the environmental information, and / or when the probability of the first driving device malfunctioning is determined to be greater than or equal to a fifth threshold based on the pose information and the motion state information.

[0408] Optionally, the rescue strategy corresponding to Level 3 may further include: sending a third distress message to the second driving device, the third distress message including the identifier of the first driving device and the location information of the first driving device, the third distress message being used to request rescue of the first driving device.

[0409] Optionally, the rescue strategy corresponding to Level 3 further includes: obtaining a fourth distress message from the third driving device, the fourth distress message including the identifier of the third driving device and the location information of the third driving device, the fourth distress message being used to request rescue of the third driving device; and sending the fourth distress message to the buoy.

[0410] Optionally, the rescue device 1000 may also include a communication module 1030, which can be used to send the first sensing data to a cloud server.

[0411] For a more detailed description of each of the above modules, please refer directly to the relevant descriptions in the embodiments of method 300 above, which will not be repeated here.

[0412] The module division in this embodiment is illustrative and represents only one logical functional division; in actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0413] It should be understood that the rescue device 1000 here is embodied in the form of functional modules. The term "module" here can refer to application-specific integrated circuits (ASICs), electronic circuits, processors (e.g., shared processors, proprietary processors, or group processors) and memory for executing one or more software or firmware programs, integrated logic circuits, and / or other suitable components supporting the described functions. For example, when a module is implemented in the form of a processing element scheduler code, the processing element can be a general-purpose processor, such as a central processing unit (CPU), or other processors capable of calling program code, such as a controller. Furthermore, these modules can be integrated together to implement a system-on-a-chip (SOC).

[0414] In an optional example, those skilled in the art will understand that the rescue device 1000 may specifically be the rescue device in the above embodiments. The rescue device 1000 may be used to execute the various processes and / or steps corresponding to the rescue device in the above method embodiments. To avoid repetition, it will not be described again here.

[0415] The rescue device 1000 described above has the function of implementing the corresponding steps performed by the rescue device in the above method; the above function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above function. In the embodiments of this application, Figure 10 The rescue device 1000 in the middle can also be a chip.

[0416] Figure 11 This is another schematic block diagram of the rescue device provided in the embodiments of this application.

[0417] like Figure 11 As shown, the rescue device 1100 can be a chip system; or it can be a device configured with a chip system to implement the method shown in the above method embodiments. In the embodiments of this application, the chip system can be composed of chips, or it can include chips and other discrete devices.

[0418] like Figure 11 As shown, the rescue device 1100 may include a processor 1110, which can be used to execute computer programs or instructions in memory to perform various steps and / or processes corresponding to the rescue device in the above method embodiments.

[0419] In one possible implementation, the rescue device 1100 further includes a communication interface 1120. The communication interface 1120 can be used to communicate with other devices via a transmission medium, thereby enabling the rescue device 1100 to communicate with other devices. The communication interface 1120 may be, for example, a transceiver, an input / output interface, a pin, a bus, a transceiver circuit, or a device capable of transmitting and receiving functions. The processor 1110 can utilize the communication interface 1120 to input and output data for executing the various steps and / or processes corresponding to the first or second processing unit in the above method embodiments.

[0420] In one possible implementation, the rescue device 1100 further includes at least one memory 1130 for storing program instructions and / or data. The memory 1130 is coupled to the processor 1110. The coupling in this embodiment is an indirect coupling or communication connection between devices, units, or modules, and can be electrical, mechanical, or other forms, for information exchange between devices, units, or modules. The processor 1110 may operate in conjunction with the memory 1130. The processor 1110 may execute the program instructions stored in the memory 1130.

[0421] Optionally, the memory 1130 may be a memory disposed in the rescue device 1100. Exemplarily, the memory 1130 may be integrated with the processor 1110; or, the memory 1130 may be disposed separately from the processor 1110.

[0422] Optionally, the memory 1130 can be a memory other than the rescue device 1100. It may also be a memory other than the rescue device 1100.

[0423] This application embodiment also provides a driving device, which is equipped with a rescue device for implementing the above-described method 300.

[0424] Alternatively, the driving device may be a vehicle.

[0425] As an example and not a limitation, a vehicle may include, but is not limited to, one or more of the following: cars, trucks, vans, buses, recreational vehicles, amusement park vehicles, golf carts, etc.

[0426] This application also provides a chip or chip system. The chip or chip system includes a processor, which calls a computer program stored in memory to execute the technical solutions described in the above embodiments. Its implementation principle and technical effects are similar to the related embodiments described above, and will not be repeated here.

[0427] This application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, it implements the methods described above. The methods described in the above embodiments can be implemented wholly or partially by software, hardware, firmware, or any combination thereof. If implemented in software, the functionality can be stored as one or more instructions or code on or transmitted over the computer-readable medium. The computer-readable medium can include computer storage media and communication media, and can also include any medium that can transfer a computer program from one place to another. The storage medium can be any target medium accessible by a computer.

[0428] In one possible implementation, a computer-readable medium may include random access memory (RAM), read-only memory (ROM), compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage or other magnetic storage devices, or any other medium intended to carry or store required program code in the form of instructions or data structures, and accessible by a computer. Furthermore, any connection is appropriately referred to as a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disks and optical discs include optical discs, laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically, while optical discs optically reproduce data using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0429] This application provides a computer program product, which includes a computer program that, when run, causes a computer to perform the above-described method.

[0430] It should be noted that the modules or components in the above embodiments can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), etc. Furthermore, when a module is implemented through processing element scheduler code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors capable of calling program code, such as a controller. Additionally, these modules can be integrated together to implement a system-on-a-chip (SOC).

[0431] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, DSL) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0432] The term "multiple" in this document refers to two or more. The term "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Furthermore, the character " / " in this document generally indicates an "or" relationship between the preceding and following related objects; in formulas, the character " / " indicates a "division" relationship between the preceding and following related objects. Additionally, it should be understood that in the description of the embodiments of this application, terms such as "first" and "second" are used only for descriptive purposes and should not be construed as indicating or implying relative importance or order.

[0433] The various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application.

[0434] In the embodiments of this application, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

Claims

1. A rescue method, characterized in that, The method includes: Acquire first perception data, which includes at least two of the following: environmental information of the first driving device, external perception information of the main body of the first driving device, position and posture information of the first driving device, motion state information of the first driving device, environmental information inside the cockpit of the first driving device, occupant behavior information, and occupant physiological state information. Based on the first sensed data, a first rescue strategy is executed, which is one of multiple rescue strategies.

2. The method according to claim 1, characterized in that, Based on the first sensed data, execute the first rescue strategy, including: Based on the first sensing data, the first water level of the first driving device is determined from multiple water level classifications; Based on the first level of falling into the water, a first rescue strategy corresponding to the first level of falling into the water is determined from the plurality of rescue strategies; Implement the first rescue strategy.

3. The method according to claim 2, characterized in that, The first water level is determined based on the water score and a first correspondence relationship. The first correspondence relationship includes multiple sets of water score intervals and water levels. The water score is determined based on the first sensing data and is used to indicate the water risk level of the first driving device.

4. The method according to claim 3, characterized in that, If the water-fall fraction is greater than or equal to a first threshold, the first rescue strategy is used to instruct the occupants to wait for rescue in the first driving device; or; If the water fall fraction is less than the first threshold and greater than or equal to the second threshold, the first rescue strategy is used to instruct the occupants to escape from the first driving device.

5. The method according to claim 4, characterized in that, When the water score is greater than or equal to the first threshold, the first water level is level 3, and the first rescue strategy corresponding to level 3 includes: The first driving device is kept in a sealed state. Release a buoy and send a first distress message through the buoy. The first distress message is used to request rescue for the first driving device. The first distress message includes the identifier of the first driving device and the location information of the first driving device. Oxygen was supplied to the occupants.

6. The method according to claim 4 or 5, characterized in that, When the water score is less than the first threshold and greater than or equal to the third threshold, the first water level is level 2, and the first rescue strategy corresponding to level 2 includes: The door locks of the first driving device are all in the unlocked state; Control the window of the first driving device to descend to the lowest height supported by the window; Send a second distress message, which requests rescue for the first driving device. The second distress message includes the identifier of the first driving device and the location information of the first driving device. Wherein, the third threshold is greater than the second threshold, and the third threshold is less than the first threshold.

7. The method according to any one of claims 4 to 6, characterized in that, When the water score is less than the third threshold and greater than or equal to the second threshold, the first water level is level 1, and the first rescue strategy corresponding to level 1 includes: Output a first alarm message, which indicates that the first driving device is at risk of wading through water; Wherein, the third threshold is greater than the second threshold, and the third threshold is less than the first threshold.

8. The method according to claim 5, characterized in that, The first distress message also includes first information, which includes one or more of the following: the water depth of the first driving device, the attitude of the first driving device, the number of occupants on the first driving device, the location information of the occupants, the physiological state information of the occupants, and a recommended rescue location for rescuing the occupants.

9. The method according to claim 5, characterized in that, The first rescue strategy corresponding to Level 3 also includes: According to the first cycle, the second information is sent to the buoy, the second information including one or more of the following: the position information of the first driving device, the water depth of the first driving device, the attitude of the first driving device, the physiological state information of the occupant, and the recommended rescue location for rescuing the occupant.

10. The method according to claim 5 or 6, characterized in that, If the first water level is level 2 or 3, and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: The first power module is powered off, and the second power module of the first driving device is powered on. The first power module is used to supply power to the drive motor of the first driving device, and the second power module is used to supply power to the first driving device in the event that the first power module fails or is in an abnormal state.

11. The method according to claim 7, characterized in that, If the first water level is Level 1 and the health status of the first power module of the first driving device is unhealthy, the first rescue strategy further includes: Output a second alarm message, which is used to indicate that the first power module is in an unhealthy state; The first power module is used to supply power to the drive motor of the first driving device.

12. The method according to claim 10 or 11, characterized in that, The method further includes: If, based on the environmental information, the risk of the first driving device falling into the water is determined to be greater than or equal to a fourth threshold, and / or, based on the pose information and the motion state information, the probability of the first driving device malfunctioning is determined to be greater than or equal to a fifth threshold, the health status of the first power module is detected.

13. The method according to claim 5 or 9, characterized in that, The rescue strategy corresponding to Level 3 also includes: A third distress message is sent to the second driving device. The third distress message includes the identifier of the first driving device and the location information of the first driving device. The third distress message is used to request rescue of the first driving device.

14. The method according to any one of claims 5, 9, or 13, characterized in that, The rescue strategy corresponding to Level 3 also includes: Obtain a fourth distress message from a third driving device, the fourth distress message including the identifier of the third driving device and the location information of the third driving device, the fourth distress message being used to request rescue of the third driving device; The fourth distress message is sent to the buoy.

15. The method according to any one of claims 1 to 14, characterized in that, The method further includes: The first sensed data is sent to the cloud server.

16. A rescue device, characterized in that, The rescue device includes a module for performing the method as described in any one of claims 1 to 15.

17. A rescue device, characterized in that, Including processor and memory, among which, The memory is used to store programs; The processor is used to invoke the program so that the rescue device performs the method as described in any one of claims 1 to 15.

18. A driving device, characterized in that, Includes the rescue device as described in claim 16 or 17.

19. The driving device according to claim 18, characterized in that, The driving device is a vehicle.

20. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer instructions that, when executed, cause the method as described in any one of claims 1 to 15 to be performed.

21. A computer program product, characterized in that, The computer program product includes computer program code that, when run, causes the method as described in any one of claims 1 to 15 to be performed.