A vehicle safety braking method and vehicle

CN122560982APending Publication Date: 2026-08-14GREAT WALL MOTOR CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-03
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

然而,在某些故障叠加的极端工况下,驾驶员可能在极端工况下完全丧失对车辆速度的控制权,车辆以设定巡航速度持续高速行驶,极易引发追尾、冲出道路等严重交通事故,造成人员伤亡和财产损失

Benefits of technology

[0025]根据本申请的第五方面,提供了一种计算机可读存储介质,存储介质存储有计算机程序,所述计算机程序用于执行如第一方面或第一方面中任意一种实现方式所述的方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122560982A_ABST
    Figure CN122560982A_ABST
Patent Text Reader

Abstract

This application discloses a vehicle safety braking method and vehicle, applied in the field of vehicle braking control technology. The vehicle safety braking method is executed by a decision module independent of the vehicle's electronic controller and main brake controller. When the system detects that the vehicle is in a dual failure state of continuous power output that cannot be disengaged and main brake function failure, it actively takes over the vehicle deceleration control, determines the corresponding braking force application strategy according to the vehicle speed level, and schedules different types of braking actuators across systems to collaboratively apply braking torque within their respective optimal speed ranges, forcing the vehicle to decelerate until it stops, thereby achieving safety assurance under extreme conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle braking control technology, specifically to a vehicle safety braking method and a vehicle. Background Technology

[0002] With the rapid development of automotive electronics and intelligent driving assistance systems, cruise control and adaptive cruise control have become standard features or common optional functions in modern vehicles. Under normal operating conditions, drivers can exit cruise control and regain direct control of the vehicle by pressing the brake pedal, pressing the cancel button on the steering wheel, or operating the cruise control switch. However, in extreme conditions with overlapping malfunctions, drivers may completely lose control of the vehicle's speed, causing the vehicle to continue traveling at the set cruise speed, which can easily lead to rear-end collisions, run-off, and other serious traffic accidents, resulting in personal injury and property damage. Current technology lacks a deceleration mechanism to cope with extreme conditions. When the driver is completely unable to take over vehicle speed control through normal operation, the vehicle faces the real risk of not being able to actively decelerate until it comes to a safe stop.

[0003] Therefore, how to safely reduce vehicle speed and control the vehicle within a safe speed range under extreme operating conditions has become an urgent technical problem to be solved in the field of vehicle braking control technology. Summary of the Invention

[0004] To address the aforementioned technical problems, this application is proposed. Embodiments of this application provide a vehicle safety braking method and a vehicle that, when detecting a dual failure state where continuous power output cannot be disengaged and the main braking function fails, coordinates different types of braking actuators to decelerate in a coordinated manner, ensuring occupant and road safety under extreme conditions.

[0005] According to a first aspect of this application, a vehicle safety braking method is provided, executed by a decision module independent of the vehicle's electronic controller and main brake controller, comprising: detecting whether the vehicle is in a dual failure state; wherein the dual failure state indicates that the vehicle's continuous power output function cannot be disengaged and the main braking function is simultaneously disabled; when the vehicle is in the dual failure state, acquiring the current vehicle speed; determining a corresponding braking force application strategy based on the speed range in which the current vehicle speed is located; wherein different speed ranges correspond to different types of braking actuators; and sending control commands to the corresponding type of braking actuator based on the braking force application strategy, so that the braking actuator applies braking torque within the corresponding speed range until the vehicle stops.

[0006] As one possible implementation, detecting whether the vehicle is in a dual failure state includes: monitoring a first parameter representing the active state of the vehicle's continuous power output function, a second parameter representing the driver's braking intention, and a third parameter representing the actual deceleration effect of the vehicle; determining that the vehicle is in a contradictory state when the first parameter, the second parameter, and the third parameter simultaneously meet preset contradictory conditions; and confirming that the vehicle is in the dual failure state when the duration of the contradictory state exceeds a preset time threshold.

[0007] By simultaneously monitoring three parameters representing cruise activation status, driver braking intention, and actual vehicle deceleration effect, and setting a judgment condition that contradictory states must continue for more than a preset time threshold, misjudgments caused by instantaneous sensor fluctuations or brief driver errors are eliminated, improving the accuracy of dual failure state identification and reducing unnecessary emergency braking triggered under non-extreme conditions.

[0008] As one possible implementation, before sending control commands to the corresponding type of braking actuator based on the braking force application strategy, the method further includes: acquiring external environment information; wherein, based on the external environment information, the timing or intensity parameters of the braking force application strategy are adjusted.

[0009] Before implementing forced braking, the system proactively acquires information about the external environment and adjusts the timing of braking force application or deceleration intensity accordingly. This allows the braking action to adapt to the surrounding traffic conditions, reducing the risk of secondary collisions with vehicles in front, behind, or obstacles such as curves and tunnels caused by blind braking.

[0010] As one possible implementation, the external environment information includes the presence of a vehicle ahead, a vehicle behind, and a curved or tunnel environment. Based on this external environment information, the timing or intensity parameters of the braking force application strategy are adjusted, including: when there is a vehicle ahead, and the distance between the vehicle and the vehicle ahead is less than a first preset distance, and the expected collision time is less than a preset time, an audible and visual warning is issued; when there is a vehicle behind the vehicle and there is a risk of a rear-end collision, the activation of the braking torque is delayed or the warning lights are turned on; when the vehicle is in a curved or tunnel environment, the maximum deceleration of the applied braking torque is limited.

[0011] For three typical dangerous scenarios—vehicles ahead, vehicles behind, and curves and tunnels—specific adjustment measures have been set up, such as audible and visual warnings, delayed braking or activation of warning lights, and deceleration restrictions. These measures provide clear execution rules for the environmental adaptive braking strategy, further refine safety protection in different scenarios, and reduce the probability of secondary accidents.

[0012] As one possible implementation, determining the corresponding braking force application strategy based on the speed range of the current vehicle speed includes: when the current vehicle speed is in a preset high-speed range, determining the corresponding braking force application strategy as a regenerative braking strategy; when the current vehicle speed is in a preset medium-speed range, determining the corresponding braking force application strategy as a point braking strategy; and when the current vehicle speed is in a preset low-speed range, determining the corresponding braking force application strategy as an emergency braking strategy using an electronic parking brake system.

[0013] By dividing the vehicle speed into three ranges—high speed, medium speed, and low speed—and assigning different braking methods to each range, the problem of a single braking method being unable to balance braking efficiency, stability, and safety across the entire speed range is solved, thus achieving a graded, orderly, and controllable deceleration process.

[0014] As one possible implementation, sending control commands to the corresponding type of braking actuator based on the braking force application strategy includes: sending a forced negative torque command to the motor controller based on the anti-drag energy recovery strategy to cause the vehicle to generate a target deceleration; sending a coordinated braking command to the electric stability system and the electronic parking brake system based on the intermittent braking strategy to cause the electric stability system to control the intermittent braking frequency and release rhythm, and the electronic parking brake system to perform braking; and sending a control command to the electronic parking brake system based on the emergency braking strategy of the electronic parking brake system to cause the electronic parking brake system to apply braking torque.

[0015] By sending a forced negative torque command to the motor controller, a coordinated intermittent braking command to the electric stability system and the electronic parking brake system, and a control command to the electronic parking brake system, the abstract braking strategy is transformed into control signals that can be recognized by the specific actuators. This ensures that each level of braking command can be executed accurately, realizing the transformation from decision-making to hardware action.

[0016] As one possible implementation, the method further includes: when the reverse drag energy recovery strategy is executed in the high-speed range, if the motor temperature is detected to be greater than a preset temperature threshold, the reverse drag force is reduced; when the reverse drag energy recovery strategy is executed in the high-speed range, if the battery state of charge is detected to be fully charged, the method switches to a point braking strategy.

[0017] When performing reverse drag energy recovery in the high-speed range, the motor temperature and battery charge status are monitored in real time. When the motor overheats, the reverse drag force is automatically reduced to protect the motor. When the battery is fully charged, it automatically switches to the intermittent braking strategy to maintain braking continuity, thus avoiding the interruption of the braking process due to the failure of the reverse drag function caused by adverse operating conditions.

[0018] As one possible implementation, the method further includes: sending a heartbeat detection signal to the vehicle's electronic controller; if no response signal is received from the electronic controller within a preset number of times, it serves as a redundancy check condition for the dual failure state, increasing the confidence level of confirming the failure of the electronic controller.

[0019] By employing an independent heartbeat detection mechanism, the confidence level for confirming the failure of the electronic controller is increased when no response signal is received from the electronic controller within a preset number of attempts. This provides an objective and quantifiable redundant verification condition for dual failure states, enhancing the accuracy of the judgment on the key criterion of whether the electronic controller has crashed or its logic is stuck.

[0020] As one possible implementation, before sending a control command to the corresponding type of brake actuator based on the braking force application strategy, the method further includes: outputting a prompt message and initiating a delay window for waiting for a response; wherein the prompt message includes: informing the driver that emergency braking avoidance is about to be initiated and prompting the driver to grip the steering wheel tightly; if no stop command is received from the driver within the delay window, the braking force application strategy continues to be executed.

[0021] Before implementing the braking force application strategy, the system provides a prompt to the driver and initiates a delay window, allowing the driver to choose to stop braking in non-emergency situations. This preserves the system's proactive emergency response capability while giving the driver ultimate control, avoiding the forced deprivation of the driver's operating authority in correctable abnormal conditions, and improving the safety and acceptability of human-machine interaction.

[0022] According to a second aspect of this application, a vehicle is provided, comprising: an electronic controller; a main brake controller; a plurality of different types of brake actuators; and a decision module independent of the electronic controller and the main brake controller; the decision module is communicatively connected to the plurality of different types of brake actuators, the decision module is signal-connected to the electronic controller, and the decision module is signal-connected to the main brake controller; wherein the decision module is configured to perform a vehicle safety braking method as described in the first aspect or any implementation thereof.

[0023] According to a third aspect of this application, a vehicle safety braking device is provided, comprising: a detection module for detecting whether the vehicle is in a dual failure state; wherein the dual failure state indicates that the vehicle's continuous power output function cannot be disengaged and the main braking function is simultaneously disabled; an acquisition module for acquiring the current vehicle speed when the vehicle is in the dual failure state; a determination module for determining a corresponding braking force application strategy based on the speed range in which the current vehicle speed is located; wherein different speed ranges correspond to different types of braking actuators; and a sending module for sending control commands to the corresponding type of braking actuator based on the braking force application strategy, so that the braking actuator applies braking torque within the corresponding speed range until the vehicle stops.

[0024] According to a fourth aspect of this application, a computer device is provided, the computer device comprising: one or more processors; a memory; and one or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the processor to implement the method as described in the first aspect or any implementation thereof.

[0025] According to a fifth aspect of this application, a computer-readable storage medium is provided, the storage medium storing a computer program for performing the method as described in the first aspect or any implementation thereof.

[0026] According to a sixth aspect of this application, an electronic device is provided, including a module for performing the method as described in the first aspect or any implementation thereof.

[0027] According to a seventh aspect of this application, a computer program product is provided, comprising program code for performing the method as described in the first aspect or any implementation thereof.

[0028] The vehicle safety braking method and vehicle provided in this application firstly introduce a decision-making module that is physically and logically independent of the original vehicle's failed main system. This module serves as a safety redundancy core, ensuring that even in the extreme case of complete paralysis of the original control system, an autonomous control entity remains, providing a reliable control foundation for all subsequent detection and execution actions. Secondly, it identifies the dual failure state of cruise control failure and main brake failure occurring simultaneously, providing a triggering condition for initiating the forced braking process and ensuring that emergency response is initiated only in truly necessary extreme scenarios. Then, it acquires the current vehicle speed in real time, enabling the braking force application strategy to make dynamic decisions based on the vehicle's current actual motion state. Next, it segments the deceleration process according to speed ranges and, based on the dynamic characteristics of different ranges, calls upon the optimal braking actuator for each range, ensuring that each stage within the full speed range utilizes the physical advantages of the corresponding mechanism to achieve deceleration. Finally, through an independent command link, multiple different types of braking actuators are actually activated and coordinated to work together, applying braking torque in their respective optimal speed ranges to force the vehicle to decelerate until it stops. This overcomes the problem that the driver loses speed control ability and cannot safely control the vehicle speed in extreme double failure scenarios, improves the vehicle's safety assurance capability in extreme situations, and enhances the safety of occupants and the road under extreme conditions. Attached Figure Description

[0029] The above and other objects, features, and advantages of this application will become more apparent from the more detailed description of the embodiments of this application in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the embodiments of this application to explain this application and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0030] Figure 1 This is a schematic flowchart of a vehicle safety braking method provided in an exemplary embodiment of this application.

[0031] Figure 2 This is a schematic diagram of the structure of a vehicle safety braking device provided in an exemplary embodiment of this application.

[0032] Figure 3 This is a structural diagram of an electronic device provided in an exemplary embodiment of this application. Detailed Implementation

[0033] Hereinafter, exemplary embodiments according to this application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments of this application. It should be understood that this application is not limited to the exemplary embodiments described herein.

[0034] In the field of vehicle constant speed control, to achieve constant vehicle speed maintenance during cruise control or adaptive cruise control, existing technologies generally embed cruise control functions into the vehicle's power domain controller. The controller collects wheel speed signals, brake pedal status signals, and cruise control button signals, and constructs a closed-loop control circuit for vehicle speed by adjusting the engine throttle opening or drive motor output torque. When the driver presses the brake pedal or triggers a cancellation command, the controller recognizes the exit condition, immediately terminates power output, and switches back to manual driving mode. However, when the cruise control function malfunctions and cannot exit, and the main braking function also fails simultaneously, the highly integrated control architecture will expose safety hazards. For example, if the power domain controller cannot recognize the brake pedal signal due to program deadlock or hardware failure, the cruise function will continue to output power, while the main braking system will also be unable to establish braking force due to hydraulic circuit failure or controller command channel blockage. In this dual failure state, the driver completely loses the ability to intervene in vehicle speed, posing an extremely high safety risk.

[0035] The aforementioned safety hazards can be attributed to the combined effect of three factors: First, there is a single-point dependence on control, meaning that both cruise control and main braking control rely on the normal operation of the same electronic controller. If the electronic controller fails, it cannot disengage cruise control or issue braking commands to the main braking system. Second, there is a singular braking execution path; main braking failure means the vehicle loses its most efficient active deceleration method and lacks other independently available braking resources. Finally, there is a lack of decision-making logic; the vehicle is not equipped with a dedicated independent decision-making mechanism to identify such complex failure conditions. Even if some actuators still possess residual capabilities, they cannot be activated due to the lack of an effective decision-making source.

[0036] Therefore, to overcome the above problems, this application proposes a vehicle safety braking method and vehicle. A decision module physically independent of the electronic controller and the main brake controller is deployed in the vehicle. This decision module executes a tiered braking process: after determining that the vehicle has entered a double failure state where continuous power output cannot be withdrawn and the main brake function is simultaneously disabled, the corresponding type of brake actuator is invoked to apply braking torque according to the current speed range of the vehicle, until the vehicle stops. Thus, by decoupling the decision-making power from the failed main controller and establishing a tiered invocation mechanism across actuators, the vehicle's deceleration control capability is restored without relying on the main controller's decision and the main brake circuit, maintaining the ability to force the vehicle to decelerate and stop even under extreme conditions.

[0037] The following describes a vehicle safety braking system deployed within a vehicle. This system is independent of the vehicle's electronic controller and main brake controller at the physical hardware, power supply, and communication levels. The vehicle safety braking system consists of three main modules working collaboratively to form a complete perception-determination-execution closed loop: First, the perception module (independent of the main system's multi-source signal acquisition) includes multiple independent signal acquisition channels: the first signal acquisition channel is connected to a sensing element characterizing the activation state of the vehicle's continuous power output function (such as cruise control or adaptive cruise control), used to independently monitor the first parameter that the continuous power output function cannot be deactivated (e.g., whether cruise control is active); the second signal acquisition channel is connected to a redundantly configured brake pedal depth sensor and brake line hydraulic sensor, used to independently monitor the driver's second parameter (e.g., pedal depth, hydraulic pressure); the third signal acquisition channel is connected to wheel speed sensors, used to acquire the third parameter reflecting the actual deceleration effect of the vehicle (e.g., vehicle speed change rate); the environmental perception component, through a dedicated data interface, connects to external environmental perception components independent of the electronic controller's information processing link, such as a forward-facing camera module (for acquiring images of the front), millimeter-wave radar (for acquiring the distance and relative speed of targets ahead), and corner radar (for acquiring the distance and relative speed of targets behind).

[0038] Second, the decision-making module, independent of the vehicle's main ECU and main brake controller. This module is either built into or externally integrated into a separate embedded domain controller, possessing its own processing chip, memory, and operating environment. The decision-making module can be configured as an AI agent with the following functions: dual failure state determination: based on three independent signals (first parameter, second parameter, and third parameter) collected by the perception module, it runs a preset dual failure determination formula to identify the contradictory state of cruise control being on while the brakes are applied but the vehicle speed does not decrease. Only when this contradictory state persists for more than a preset time threshold (e.g., 2 seconds) does the AI ​​agent confirm the entry into a dual failure state; safe corridor confirmation: after confirming entry into emergency mode, the AI ​​agent calls upon data from the environmental perception components to assess the surrounding environment (vehicles ahead, behind, or the presence of curves / tunnels) and generate safe corridor information; strategy selection and command generation: based on the assessed environmental information and current vehicle speed, the AI ​​agent selects and generates corresponding three-level progressive braking strategy commands (e.g., motor reverse braking, intermittent braking, and emergency parking).

[0039] Third, the execution module and the decision module's output end establish control connections with multiple different types of braking actuators through independent control buses: the first control output end is connected to the motor controller through an independent CAN (Controller Area Network) bus to send forced negative torque commands; the second control output end is connected to the controllers of the electronic parking brake system (EPB) and the electronic stability system (ESC); the third control output end is connected to the controller of the electronic parking brake system (EPB).

[0040] Furthermore, the decision-making module can connect to human-machine interface components (instrument panel, speakers) to send prompts to the instrument display module and sound playback module. Additionally, a one-button cancellation button can be installed in the passenger compartment. When triggered, the cancellation command generated can be received by the decision-making module in real time, allowing for timely cancellation of forced deceleration. The decision-making module can also integrate internally or connect externally to a recording module for data storage, continuously recording status and decision data generated during system operation.

[0041] By using the vehicle safety braking system, a completely independent perception-decision-execution link is achieved, enabling a complete safe stopping closed loop when the driver loses control of the speed, thereby improving the safety braking effect.

[0042] Figure 1 This is a schematic flowchart of a vehicle safety braking method provided in an exemplary embodiment of this application, which is described below in conjunction with... Figure 1 This application provides a detailed description of the vehicle safety braking method provided in the embodiments.

[0043] In S110, it detects whether the vehicle is in a dual failure state.

[0044] The dual failure state signifies that the vehicle's continuous power output function cannot be disengaged, and the main braking function also fails simultaneously. For example, the continuous power output function (such as cruise control or adaptive cruise control) cannot respond to a normal disengagement command due to logic lock-up, communication interruption, or component malfunction, while the main braking function is completely unable to provide effective braking due to loss of power assist, hydraulic circuit leakage, or controller failure. Alternatively, it is equivalent to a combined failure where the driver actively applies the brakes but the vehicle cannot physically produce a corresponding deceleration effect. Or any combination of the above conditions. The dual failure state means that the driver cannot terminate continuous power output functions such as cruise control through normal operation, nor can they establish effective braking force by pressing the brake pedal, leaving the vehicle in a dangerous situation of speed loss.

[0045] In some embodiments, the process of detecting a dual failure state involves the acquisition and comprehensive logical judgment of multi-source heterogeneous signals. The decision module monitors a first parameter characterizing the activation state of the vehicle's continuous power output function, a second parameter characterizing the driver's braking intention, and a third parameter characterizing the actual deceleration effect of the vehicle, respectively, through independent signal acquisition channels. For example, the decision module connects to the sensing element characterizing the vehicle's continuous power output function state through the first signal acquisition channel to obtain the activation or operating signal of the function, such as the cruise control activation status flag, as the first parameter. The decision module connects to the brake pedal depth sensor and the brake line hydraulic sensor through the second signal acquisition channel to obtain the percentage value of the brake pedal depressing depth relative to the maximum travel and the real-time hydraulic pressure value in the brake line, as the second parameter. The decision module connects to the wheel speed sensor through the third signal acquisition channel to obtain the change in vehicle speed per unit time, such as the vehicle's deceleration, as the third parameter.

[0046] The vehicle is determined to be in a contradictory state when the first, second, and third parameters simultaneously meet preset contradictory conditions. The contradictory conditions aim to capture a physically contradictory operating condition: the continuous power output function is still instructing the vehicle to maintain or increase speed, the driver explicitly performs a hard braking operation, but the vehicle does not actually exhibit the expected deceleration effect. For example, the contradictory conditions could be set as follows: the first parameter indicates that the cruise control function is actively engaged; the second parameter indicates that the driver has pressed the brake pedal deeper than a preset percentage threshold (e.g., 80% of the full travel), or the hydraulic pressure in the brake lines is lower than a preset minimum pressure threshold for effective braking (e.g., lower than the lower limit of pressure for effective braking); and the third parameter indicates that within a preset time period (e.g., within two seconds), the decrease in vehicle speed is less than a preset speed change threshold (e.g., the decrease is less than two kilometers per hour).

[0047] Furthermore, to avoid misjudgments caused by instantaneous changes in sensor signals or brief accidental touches by the driver, the duration of the contradictory state is monitored after determining that the vehicle is in a contradictory state. Only when the duration of the contradictory state exceeds a preset time threshold (e.g., two seconds) is the vehicle finally confirmed to have entered a dual failure state. The introduction of the time threshold constitutes a software-level filtering mechanism, improving the flexibility of the system's judgment.

[0048] To further enhance the diagnostic confidence of electronic controller failure as a prerequisite, an active verification mechanism can be configured. This involves sending a heartbeat detection signal to the vehicle's electronic controller. If no response signal is received from the electronic controller within a preset number of consecutive cycles (e.g., three), it serves as a redundant verification condition for a dual failure state, increasing the confidence in confirming electronic controller failure. This diagnostic mechanism provides physical evidence of electronic controller failure from the perspective of the communication link handshake, reducing the probability of false alarms caused by interference such as momentary interruptions in the communication bus. Here, failure refers to the controller losing its ability to respond to external requests or perform expected control functions within a preset time due to hardware malfunction, software deadlock, or communication interruption.

[0049] In other embodiments, besides determining the driver's braking intention by monitoring whether the depth of the brake pedal exceeds a preset percentage threshold, to improve redundancy, monitoring of the brake line pressure sensor values ​​can be added. When the pressure value is below a preset threshold and the pedal depth meets the requirement, it further confirms the possibility of brake system failure. Furthermore, wheel lock-up trend data monitored by wheel speed sensors can also serve as a redundancy criterion: if the wheels do not exhibit the expected lock-up or slip ratio change after the driver depresses the brake pedal, it can also help confirm brake failure. The fusion of multiple signals can improve the system's detection stability under complex operating conditions.

[0050] In S120, when the vehicle is in a dual failure state, the current vehicle speed is obtained.

[0051] After confirming the dual failure state, the decision-making module obtains the vehicle's current speed in real time from wheel speed sensors or other sensing elements that can provide vehicle speed information. The current vehicle speed is the benchmark parameter for subsequent hierarchical decision-making on braking force application strategies.

[0052] In S130, the corresponding braking force application strategy is determined based on the current speed range of the vehicle.

[0053] The type of braking actuator used varies depending on the speed range.

[0054] For example, the speed range can be divided into at least three ranges: high speed range, medium speed range and low speed range, and a braking actuator best suited to the operating characteristics can be matched to each range.

[0055] As one possible implementation, the decision module obtains the current vehicle speed and compares it with a preset speed threshold. When the current vehicle speed is in a preset high-speed range (e.g., greater than or equal to 80 km / h), the corresponding braking force application strategy is determined to be a regenerative braking strategy, which mainly utilizes the vehicle's drive motor to generate negative torque to achieve deceleration. When the current vehicle speed is in a preset medium-speed range (e.g., between 20 km / h and 80 km / h), the corresponding braking force application strategy is determined to be a point braking strategy, which mainly involves the electronic parking brake system and the electronic stability system working together to perform intermittent braking in a pulse manner. When the current vehicle speed is in a preset low-speed range (e.g., less than 20 km / h), the corresponding braking force application strategy is determined to be an emergency braking strategy using the electronic parking brake system, which continuously applies the maximum parking force to stop the vehicle.

[0056] The method of matching braking actuators according to vehicle speed ranges allows each type of actuator to operate within its optimal efficiency and safety range, thus overcoming the adaptability limitations of a single braking method across the entire speed range. For example, in the high-speed range, the motor reverse drag achieves a smooth deceleration with low friction and no heat fade; in the medium-speed range, the intermittent braking mode simulates the anti-lock braking function, preventing fishtailing caused by rear wheel lock-up; and in the low-speed range, directly applying the electronic parking brake achieves a reliable final parking.

[0057] To optimize the vehicle's adaptability to complex external environments during forced braking and prevent secondary accidents such as rear-end collisions and rollovers caused by blind braking, the method may include an environmental perception and strategy adjustment phase before sending control commands to the braking actuator based on the braking force application strategy. The decision module acquires external environmental information through a dedicated data interface. For example, the external environmental perception components connected to the decision module include at least a forward-facing camera module, millimeter-wave radar, and corner radar, used to acquire external environmental information such as the image of the vehicle ahead, the distance and relative speed of objects ahead, and the distance and relative speed of objects behind. After acquiring the external environmental information, the timing or intensity parameters of the braking force application strategy to be executed are adjusted to match the braking behavior with the surrounding traffic and road conditions, balancing the primary goal of braking to a stop with the safety constraints of collision risk avoidance.

[0058] As one possible approach, external environmental information encompasses typical risk scenarios such as vehicles ahead, vehicles behind, and environments with curves or tunnels. Adjusting the braking force application strategy based on this information can be concretized into a series of targeted response measures: When there are no vehicles in front of the vehicle and no vehicles following closely behind, the braking force application strategy can be executed directly.

[0059] When there is a vehicle in front of the vehicle, if the distance between the vehicle and the vehicle in front is less than the first preset distance and the estimated collision time is less than the preset time, it indicates that there is a high risk of forward collision. At this time, instead of immediately implementing physical braking, the vehicle will first implement an audible and visual warning, which will warn the driver of the vehicle and the vehicle in front by driving the vehicle lights and horn. This can give the vehicle in front time to react in non-emergency collision scenarios, or wake up the distracted driver. If possible, the problem can be solved by prioritizing the warning.

[0060] When there is a vehicle behind you and there is a risk of rear-end collision, for example, if the distance to the following vehicle is less than a certain threshold and the relative speed between the two vehicles indicates that your speed is lower than the speed of the following vehicle, suggesting that the following vehicle is rapidly approaching, immediately applying full braking in this situation could easily cause a rear-end collision. Therefore, you can delay the activation of braking torque or activate the hazard lights. Delaying the activation, for example, by postponing the braking action by 0.5 seconds, provides the driver of the following vehicle with time to observe and react, while activating the hazard lights sends a warning signal to the vehicle behind.

[0061] When a vehicle is in a curved or tunnel environment, its stability boundary narrows and road surface adhesion conditions may be poor. In such cases, it is necessary to limit the maximum deceleration of the applied braking torque, for example, by limiting the maximum deceleration to below 0.3g. By limiting the braking intensity, it is possible to prevent the vehicle from skidding or fishtailing due to excessive braking force in curves, or from losing control due to changes in visibility and road surface conditions in tunnels.

[0062] In S140, based on the braking force application strategy, a control command is sent to the corresponding type of braking actuator to cause the braking actuator to apply braking torque within the corresponding vehicle speed range until the vehicle stops.

[0063] The decision module generates specific control commands that match the corresponding braking actuator based on the selected braking force application strategy and sends them out through an independent control link. For example, the first control output of the decision module is connected to the motor controller via a bus to send commands to adjust the torque output of the drive motor. The second control output of the decision module is connected to the controller of the electronic stability system, and the third control output is connected to the controller of the electronic parking brake system. When the reverse drag energy recovery strategy is executed, the decision module sends a forced negative torque command to the motor controller to switch the drive motor from driving mode to generating mode, applying a reverse torque to the drive shaft to generate a target deceleration, such as a deceleration of 0.2g to 0.3g for the vehicle. When the intermittent braking strategy is executed, the decision module sends coordinated intermittent braking commands to the electronic stability system and the electronic parking brake system, such as controlling the electronic parking brake system to perform high-frequency pulsed braking with a period of 0.5 seconds, performing braking for 0.2 seconds and releasing for 0.3 seconds in each cycle, while the electronic stability system synchronously monitors the wheel slip ratio and vehicle yaw angle to prevent wheel lock-up. When the emergency braking strategy of the electronic parking brake system is executed, the decision module directly sends a braking command to the electronic parking brake system to continuously apply its maximum parking force until the vehicle comes to a complete stop and automatically engages the parking gear.

[0064] Understandably, the decision-making module sends control commands to the motor controller via a CAN bus independent of the main controller's communication link. In another implementation, considering the need for higher bandwidth and real-time performance, control commands can also be transmitted via automotive Ethernet or FlexRay (a real-time deterministic communication bus). Ethernet supports larger data volumes and is suitable for scenarios requiring simultaneous transmission of environmental perception data; FlexRay, with its deterministic time-triggered communication mechanism, can more accurately ensure that the transmission delay of braking commands remains within a predictable range. Regardless of the protocol used, an end-to-end security authentication mechanism is employed between the decision-making module and the braking actuator to ensure the integrity of the commands.

[0065] As one possible implementation, during the execution of the intermittent braking strategy, the decision-making module obtains the slip ratio of each wheel and the vehicle yaw angle in real time through the electronic stability system. Based on this, the decision-making module executes a closed-loop control logic: when the slip ratio of any wheel exceeds a preset anti-lock braking threshold (e.g., 20%), it immediately instructs the electronic parking brake system to reduce or suspend the braking pressure on that wheel and increase the release cycle to prevent wheel lock-up; when the rate of change of the vehicle yaw angle is detected to exceed a preset stability threshold (e.g., 10 degrees / second), it not only adjusts the intermittent braking frequency to reduce lateral force imbalance, but also sends a corrective auxiliary torque request to the electric power steering system to help the driver maintain the vehicle's directional stability and prevent fishtailing.

[0066] As one possible implementation, the decision module generates a corresponding set of instructions for applying three different braking forces: For example, based on an anti-traction energy recovery strategy, a forced negative torque command is sent to the motor controller. This command explicitly specifies the magnitude of the negative torque or target deceleration value that the motor needs to output. For instance, the command might include a torque request value required to achieve a deceleration of 0.2g to 0.3g, causing the vehicle to produce the target deceleration. The motor controller responds to this command by controlling the drive motor to perform energy recovery, converting the vehicle's kinetic energy into electrical energy, while simultaneously applying a braking effect to the wheels.

[0067] For example, based on a point-and-click braking strategy, coordinated point-and-click braking commands are sent to the electric stability system and the electronic parking brake system. The commands sent to the electronic parking brake system control its actuators to perform clamping and releasing actions at a preset frequency, so that the electronic parking brake system can perform braking. The commands sent to the electronic stability system are used to coordinate its monitoring functions, transmit wheel slip ratio and other statuses in real time, and may include sub-commands to intervene in the point-and-click braking frequency or request additional braking when an unstable trend is detected, so that the electric stability system can control the point-and-click braking frequency and release rhythm.

[0068] For example, based on the emergency braking strategy of the electronic parking brake system, a control command is sent to the electronic parking brake system to cause it to apply braking torque. The control command instructs the electronic parking brake system to directly apply and maintain the maximum parking braking torque within its design range, without periodically releasing it, until a termination command is received or the vehicle comes to a complete stop.

[0069] By generating corresponding instructions, a clear instruction mapping relationship is established from the decision-making level to the execution level, ensuring that the braking force application strategy at each level can be reliably executed to achieve the expected deceleration, anti-lock braking and parking effects.

[0070] In another possible implementation, for vehicles equipped with a brake-by-wire system (EHB or EMB), the decision module can also directly send a pressure build-up command to the brake-by-wire system. The brake-by-wire system uses its independent redundant motor to quickly build up braking pressure, achieving precise and smooth pressurization and release of the brake wheel cylinders, thereby simulating the effect of intermittent braking.

[0071] When implementing the reverse drag energy recovery strategy in the high-speed range, the drive motor and power battery may encounter physical boundaries, leading to performance degradation or even failure of the reverse drag function. To address this issue, a protection strategy can be implemented. This involves continuously monitoring the real-time temperature of the motor and the state of charge of the battery during high-speed reverse drag energy recovery. The decision module has a preset temperature threshold, such as 120 degrees Celsius. If the detected motor temperature exceeds the preset threshold, it indicates that the motor is approaching its thermal protection limit. Continuing full-load reverse drag poses a risk of damage. In this case, the reverse drag force is reduced, for example, by decreasing the requested negative torque value to reduce the motor's braking power, keeping its temperature within a safe range and preventing thermal damage to critical components.

[0072] Simultaneously, the battery's state of charge (SOC) is monitored. When the reverse drag energy recovery strategy is executed in the high-speed range, if the battery's SOC is detected to be fully charged, it cannot accept any more recovered energy. Continuing reverse drag may trigger overcharge protection or cause the reverse drag braking effect to disappear. Once this boundary condition is detected, the decision module will directly terminate the current first-level reverse drag strategy and switch to and initiate the second-level intermittent braking strategy, with the intermittent braking mechanism taking over the subsequent deceleration task. Through preset physical protection boundaries and automatic switching logic, the decision achieves a balance between component self-protection and the continuity of safe braking, avoiding interruptions in the safe braking process due to the actuator's own protective shutdown.

[0073] Before confirming the dual failure state and preparing to execute forced braking, a human-machine interaction confirmation strategy can be provided to mitigate the conflict of human-machine control and preserve the driver's final intervention opportunity while still conscious. Specifically, before sending control commands to the corresponding type of braking actuator based on the braking force application strategy, the decision module outputs a prompt message to the driver through a human-machine interaction component. This prompt message may include informing the driver that emergency braking is about to be initiated and reminding the driver to grip the steering wheel firmly to cope with the impending deceleration. Simultaneously with outputting the prompt message, a delay window is initiated to await the driver's response. The duration of the delay window is preset, for example, three seconds. During this period, the decision module listens for commands from input devices such as cancel buttons. If a stop command is received from the driver within the delay window, the automatic braking process is suspended, and control of the vehicle is preferentially returned to the driver. If no stop command is received by the end of the delay window, it is determined that the driver may be incapacitated or unable to operate correctly due to panic, and the braking force application strategy continues to be executed. By incorporating a human-machine arbitration mechanism, in extreme operating conditions where the automatic system must intervene, the driver's final decision-making power is respected and preserved, thus avoiding additional risks caused by conflicts between human and machine intentions.

[0074] Understandably, the driver's abort command can be made by pressing the cancel button or by explicitly confirming the abort via voice command.

[0075] There is a prerequisite for the human-machine interaction confirmation process: the confirmation step is initiated only when the acquired external environmental information determines that the current situation is not an emergency collision scenario. For example, the human-machine interaction confirmation process will only begin to output prompt information to the driver through the human-machine interaction component when the time to collision (TTC) with the vehicle in front is determined to be greater than a high safety threshold (e.g., 5 seconds) and there is no immediate risk of a rear-end collision.

[0076] To further enhance safety during forced braking and mitigate the impact on following vehicles and surrounding traffic, independent environmental perception sensors (such as a forward-facing camera) can be used to acquire lane markings, road edge information, and emergency lane markings when implementing a point-and-click braking strategy in low-to-medium speed ranges. Simultaneously, combined with navigation map data, the current road type is determined (e.g., whether it is a highway or urban expressway with an emergency lane). Once it is confirmed that the vehicle is on a road with clearly marked lanes and an emergency lane, and after confirmation via human-machine interaction (or when confirmation is not possible in an emergency collision scenario), a stop mode is activated. At this point, the decision module sends a cooperative control command to the vehicle's electric power steering (EPS) system, containing a path planning curve for the target driving trajectory. The curve aims to guide the vehicle smoothly and safely from the current lane to the nearest emergency lane, or to remain centered within the current lane.

[0077] Furthermore, the system monitors the vehicle's lateral position and heading angle deviations relative to the lane lines in real time. Based on these deviations, it dynamically calculates an auxiliary steering torque request value using a preset PID or Model Predictive Controller (MPC) algorithm. This request value is sent to the EPS controller via a separate communication link. Upon receiving the request, the EPS controller overlays it onto the driver's potential steering maneuvers, making minor directional corrections to guide the vehicle smoothly towards the center of the lane or the emergency lane. During this guidance process, the system continuously monitors the vehicle's yaw angle, lateral acceleration, and the distance and speed of vehicles behind to ensure that directional corrections do not cause vehicle instability or collisions with following vehicles. For example, if a following vehicle is too close, the directional correction command is paused, maintaining only straight-line braking within the current lane until a safe window appears before resuming. Once the vehicle successfully stops in the emergency lane or center of the lane, the system automatically activates the electronic parking brake and engages P gear, while simultaneously displaying continuous warning lights. This reduces the risk of secondary rear-end collisions caused by the vehicle stopping in the driving lane, improving the ultimate safety of emergency avoidance.

[0078] To promptly transmit emergency information to the driver and relevant rescue platforms after the vehicle has successfully undergone forced braking and come to a safe stop, a vehicle-to-everything (V2X) remote alarm can be initiated. For example, after controlling all braking actuators to bring the vehicle to a complete stop, automatically engaging parking gear, and activating the electronic parking brake (EPB), a set of alarm data is generated and sent via an independent interface connected to the decision module and the onboard remote communication terminal (T-Box). The alarm data is uploaded to a cloud server via a mobile communication network (such as 4G / 5G). The alarm data may include an event type code (e.g., a predefined double-failure emergency braking code), the precise time of the event, the GPS coordinates of the vehicle when it stopped, the vehicle identification number (VIN), and a brief description of the final stopping state (e.g., stopped in the emergency lane or stopped in the center of the original lane). Upon receiving the alarm information, the cloud server can, according to preset rules, send alerts to the vehicle owner's pre-set contact mobile phone, the fleet management platform, or the roadside assistance service center via SMS, application push notifications, or telephone.

[0079] In some embodiments, the sending of alarm information can also be associated with a human-machine interaction confirmation process. If the driver issues a stop command within the delay window, not only will the braking command be abandoned, but the process of automatically sending remote alarm information will also be canceled to avoid generating unnecessary alarms in non-emergency situations. Conversely, once the automatic braking process is completed, the remote alarm information will be automatically sent without driver intervention, ensuring that the danger information is conveyed.

[0080] In some embodiments, after the vehicle comes to a complete stop through the braking force application strategy, the decision module can also execute differentiated auxiliary safety measures based on the final road environment where the vehicle is located. For example, if the perception module detects that the vehicle is stopped in the center of a highway lane, the decision module controls the vehicle to keep the hazard warning lights illuminated and automatically dials an emergency rescue number through the vehicle-to-everything (V2X) system to request external assistance. If the vehicle is parked near the emergency lane and sensors confirm that there are no vehicles approaching from behind or to the side, the decision module applies a slight and smooth steering torque through the electric power steering system to guide the vehicle fully into the emergency lane and automatically engages the parking gear after stopping. If the vehicle stops on a slope, to prevent it from rolling away, the decision module instructs the electronic parking brake system to maintain maximum parking force output, while locking the transmission in the parking gear through the powertrain controller, ensuring that the vehicle remains stationary even when no one is present. These measures further enhance the system's practicality in extreme conditions, reducing the impact on traffic flow and the risk of secondary accidents.

[0081] To ensure system traceability and safety analysis, the entire process of implementing vehicle safety braking can be monitored and recorded. This monitoring and recording process is initiated synchronously by the decision-making module when executing any step. For example, the decision-making module activates a dedicated data recording unit independent of the vehicle's main storage module. This dedicated data recording unit employs a damage-resistant design (e.g., an independent black box). The recorded content can include: the precise time of triggering the dual failure mode, the current vehicle speed, and the brake pedal depth; decision logs generated by the decision-making module for each step, including the timestamp of the decision and its basis (such as environmental assessment results and speed range determination); execution parameters during braking, including motor torque values, pressure values ​​applied by the electronic parking brake system, and real-time vehicle speed change curves. Additionally, it includes environmental data acquired by the perception module, such as distance to the vehicle in front, distance to the vehicle behind, and road curvature. This data is encrypted and stored, and can be read afterward through a dedicated interface for fault diagnosis, liability determination, and subsequent system optimization, thereby enhancing the system's traceability capabilities.

[0082] One embodiment of this application also provides a vehicle, which includes an electronic controller, a main brake controller, and multiple different types of brake actuators, as well as a decision module independent of the electronic controller and the main brake controller. The architecture of the decision module can be referenced in a vehicle safety braking system. The decision module is communicatively connected to the multiple different types of brake actuators and has signal connections with the electronic controller and the main brake controller. Internally, the decision module includes a processor and a memory, with program instructions stored in the memory. When the program instructions are executed by the processor, the decision module implements the vehicle safety braking method provided in this application.

[0083] Figure 2 This is a schematic diagram of the structure of a vehicle safety braking device provided in an exemplary embodiment of this application, as shown below. Figure 2 As shown, the vehicle safety braking device 2 includes: a detection module 21 for detecting whether the vehicle is in a dual failure state; wherein, the dual failure state indicates that the vehicle's continuous power output function cannot be disengaged and the main braking function fails simultaneously; an acquisition module 22 for acquiring the current vehicle speed when the vehicle is in a dual failure state; a determination module 23 for determining the corresponding braking force application strategy based on the speed range of the current vehicle speed; wherein, different speed ranges correspond to different types of braking actuators; and a sending module 24 for sending control commands to the corresponding type of braking actuator based on the braking force application strategy, so that the braking actuator applies braking torque within the corresponding speed range until the vehicle stops.

[0084] As one possible implementation, the detection module 21 can be configured to: monitor a first parameter representing the active state of the vehicle's continuous power output function, a second parameter representing the driver's braking intention, and a third parameter representing the actual deceleration effect of the vehicle; when the first parameter, the second parameter, and the third parameter simultaneously meet preset contradictory conditions, determine that the vehicle is in a contradictory state; when the duration of the contradictory state exceeds a preset time threshold, confirm that the vehicle is in a dual failure state.

[0085] As one possible implementation, the vehicle safety braking device 2 can be configured to: acquire external environmental information; wherein, based on the external environmental information, adjust the timing or intensity parameters of the braking force application strategy.

[0086] As one possible implementation, the external environment information includes vehicles ahead, vehicles behind, and the presence of curves or tunnels. The vehicle safety braking device 2 can also be configured to: execute an audible and visual warning when there is a vehicle ahead, when the distance between the vehicle and the vehicle ahead is less than a first preset distance, and the expected collision time is less than a preset time; delay the activation of braking torque or activate the warning lights when there is a vehicle behind the vehicle and there is a risk of a rear-end collision; and limit the maximum deceleration of the applied braking torque when the vehicle is in a curve or tunnel environment.

[0087] As one possible implementation, the determining module 23 can be configured to: when the current vehicle speed is in a preset high-speed range, determine the corresponding braking force application strategy as a reverse drag energy recovery strategy; when the current vehicle speed is in a preset medium-speed range, determine the corresponding braking force application strategy as a point braking strategy; and when the current vehicle speed is in a preset low-speed range, determine the corresponding braking force application strategy as an emergency braking strategy using an electronic parking brake system.

[0088] As one possible implementation, the sending module 24 can be configured to: send a forced negative torque command to the motor controller based on an anti-drag energy recovery strategy to cause the vehicle to generate a target deceleration; send a coordinated braking command to the electric stability system and the electronic parking brake system based on a point braking strategy to cause the electric stability system to control the point braking frequency and release rhythm, and the electronic parking brake system to perform braking; and send a control command to the electronic parking brake system based on an emergency braking strategy to cause the electronic parking brake system to apply braking torque.

[0089] As one possible implementation, the vehicle safety braking device 2 can be configured to: reduce the anti-drag force when the motor temperature is detected to be greater than a preset temperature threshold during the execution of the anti-drag energy recovery strategy in the high-speed range; and switch to the intermittent braking strategy when the battery is detected to be fully charged during the execution of the anti-drag energy recovery strategy in the high-speed range.

[0090] As one possible implementation, the vehicle safety braking device 2 can be configured to: send a heartbeat detection signal to the vehicle's electronic controller; if no response signal is received from the electronic controller within a preset number of times, it serves as a redundancy check condition for a dual failure state, increasing the confidence level of confirming the failure of the electronic controller.

[0091] As one possible implementation, the vehicle safety braking device 2 can also be configured to: output a prompt message and initiate a delay window for waiting for a response; wherein the prompt message includes: informing the driver that emergency braking to avoid danger is about to be initiated and prompting the driver to grip the steering wheel tightly; if no stop command is received from the driver within the delay window, the braking force application strategy continues to be executed.

[0092] An electronic device includes: a processor; a memory for storing processor-executable instructions; and a processor for executing the vehicle safety braking method described in the embodiments provided in this application.

[0093] Below, for reference Figure 3 This application describes an electronic device according to embodiments thereof. The electronic device may be either or both of a first device and a second device, or a standalone device independent of them, which may communicate with the first device and the second device to receive acquired input signals from them.

[0094] Figure 3 A block diagram of an electronic device according to an embodiment of this application is illustrated.

[0095] like Figure 3 As shown, the electronic device 30 includes one or more processors 31 and memory 32.

[0096] The processor 31 may be a central processing unit (CPU) or other form of processing unit with data processing and / or instruction execution capabilities, and may control other components in the electronic device 30 to perform desired functions.

[0097] The memory 32 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 31 may execute the program instructions to implement the vehicle safety braking methods of the various embodiments of this application described above and / or other desired functions. Various contents such as input signals, signal components, and noise components may also be stored in the computer-readable storage medium.

[0098] In one example, the electronic device 30 may also include an input device 33 and an output device 34, which are interconnected via a bus system and / or other forms of connection mechanism (not shown).

[0099] When the electronic device is a standalone device, the input device 33 can be a communication network connector for receiving the collected input signals from the first device and the second device.

[0100] In addition, the input device 33 may also include, for example, a keyboard, a mouse, etc.

[0101] The output device 34 can output various information to the outside, including determined distance information, direction information, etc. The output device 34 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.

[0102] Of course, for the sake of simplicity, Figure 3 Only some of the components of the electronic device 30 relevant to this application are shown in this illustration; components such as buses, input / output interfaces, etc., are omitted. In addition, the electronic device 30 may include any other suitable components depending on the specific application.

[0103] The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of this application. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0104] A computer-readable storage medium stores a computer program for performing the vehicle safety braking method described in the embodiments provided in this application.

[0105] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.

[0106] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this application to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A vehicle safety braking method, characterized in that, Executed by a decision-making module independent of the vehicle's electronic controller and main brake controller, including: Detect whether the vehicle is in a dual failure state; wherein, the dual failure state indicates that the vehicle's continuous power output function cannot be disengaged and the main braking function fails simultaneously. When the vehicle is in the aforementioned dual failure state, obtain the current vehicle speed; Based on the current speed range, a corresponding braking force application strategy is determined; different speed ranges correspond to different types of braking actuators. Based on the braking force application strategy, control commands are sent to the corresponding type of braking actuator to cause the braking actuator to apply braking torque within the corresponding vehicle speed range until the vehicle stops.

2. The vehicle safety braking method according to claim 1, characterized in that, The detection of whether the vehicle is in a dual failure state includes: The monitoring parameters are: a first parameter representing the activation state of the vehicle's continuous power output function, a second parameter representing the driver's braking intention, and a third parameter representing the actual deceleration effect of the vehicle. When the first parameter, the second parameter, and the third parameter simultaneously satisfy the preset contradictory conditions, the vehicle is determined to be in a contradictory state. When the duration of the contradictory state exceeds a preset time threshold, the vehicle is confirmed to be in the dual failure state.

3. The vehicle safety braking method according to claim 1, characterized in that, Before sending control commands to the corresponding type of brake actuator based on the braking force application strategy, the method further includes: Obtain external environmental information; among which, Based on the external environment information, the timing or intensity parameters of the braking force application strategy are adjusted.

4. The vehicle safety braking method according to claim 3, characterized in that, The external environment information includes vehicles ahead, vehicles behind, and the presence of curves or tunnels. The adjustment of the activation timing or intensity parameters of the braking force application strategy based on the external environment information includes: When there is a vehicle in front of the vehicle, and the distance between the vehicle and the vehicle in front is less than a first preset distance, and the estimated collision time is less than a preset time, an audible and visual warning is issued. When there is a vehicle behind the vehicle and there is a risk of rear-end collision, delay the activation of braking torque or turn on the warning lights. When the vehicle is in a curved or tunnel environment, the maximum deceleration of the applied braking torque is limited.

5. The vehicle safety braking method according to claim 1, characterized in that, The step of determining the corresponding braking force application strategy based on the current vehicle speed within the specified speed range includes: When the current vehicle speed is in the preset high-speed range, the corresponding braking force application strategy is determined to be the reverse drag energy recovery strategy. When the current vehicle speed is within the preset medium speed range, the corresponding braking force application strategy is determined to be the intermittent braking strategy. When the current vehicle speed is in a preset low-speed range, the corresponding braking force application strategy is determined to be the emergency braking strategy using the electronic parking brake system.

6. The vehicle safety braking method according to claim 5, characterized in that, The step of sending control commands to the corresponding type of braking actuator based on the braking force application strategy includes: Based on the aforementioned reverse drag energy recovery strategy, a forced negative torque command is sent to the motor controller to cause the vehicle to generate a target deceleration. Based on the aforementioned intermittent braking strategy, coordinated intermittent braking commands are sent to the electric stability system and the electronic parking brake system, so that the electric stability system controls the intermittent braking frequency and release rhythm, and the electronic parking brake system performs braking. Based on the emergency braking strategy of the electronic parking brake system, a control command is sent to the electronic parking brake system to cause the electronic parking brake system to apply braking torque.

7. The vehicle safety braking method according to claim 5, characterized in that, The method further includes: When the reverse drag energy recovery strategy is executed in the high-speed range, if the motor temperature is detected to be greater than a preset temperature threshold, the reverse drag force is reduced. When the reverse drag energy recovery strategy is executed in the high-speed range, if the battery state of charge is detected to be full, the strategy is switched to point braking.

8. The vehicle safety braking method according to claim 1, characterized in that, The method further includes: Send a heartbeat detection signal to the vehicle's electronic controller; If no response signal is received from the electronic controller within a preset number of attempts, it serves as a redundancy check condition for the dual failure state, increasing the confidence level in confirming the failure of the electronic controller.

9. The vehicle safety braking method according to claim 1, characterized in that, Before sending control commands to the corresponding type of brake actuator based on the braking force application strategy, the method further includes: Output a prompt message and start a delayed window to wait for a response; wherein, the prompt message includes: informing the driver that emergency braking and avoidance are about to be initiated and reminding the driver to grip the steering wheel firmly; If no abort command is received from the driver within the delay window, the braking force application strategy continues to be executed.

10. A vehicle, characterized in that, include: Electronic controller; Main brake controller; Multiple different types of braking actuators; A decision module independent of the electronic controller and the main brake controller; The decision module is communicatively connected to the plurality of different types of braking actuators, the decision module is signal-connected to the electronic controller, and the decision module is signal-connected to the main brake controller; The decision module is configured to perform the vehicle safety braking method as described in any one of claims 1 to 9.