An unmanned vehicle control system

CN122607250APending Publication Date: 2026-08-21SHANGHAI ECAR TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610967000.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-30
Publication Date
2026-08-21

AI Technical Summary

Technical Problem

[0005]本发明实施例提供一种无人驾驶车辆控制系统,通过设置供电冗余子系统和通信冗余子系统,解决了传统无人驾驶车辆单一故障,将直接导致自动驾驶系统完全或部分丧失对制动的控制权,车辆进入不可控状态的问题

Benefits of technology

[0016]This invention provides an autonomous vehicle control system, including a power supply redundancy subsystem and an autonomous vehicle control system. The power supply redundancy subsystem includes a main power supply and an auxiliary power supply. The main power supply is electrically connected to the chassis actuators via a first power distribution circuit and a second power distribution circuit. The auxiliary power supply is directly electrically connected to the chassis actuators. The power distribution modes of the power supply redundancy subsystem include a normal power distribution mode, a first-level redundancy power distribution mode, and a second-level redundancy power distribution mode. Through these three-level power distribution modes, it is ensured that the chassis actuators can still obtain necessary power when a single power supply path or the central domain controller fails, thereby avoiding vehicle loss of control due to power outages. The autonomous vehicle control system achieves communication redundancy through three independent communication paths. Each bus and link uses independent wiring harnesses and hardware interfaces to achieve physical-level fault isolation. Under normal operating conditions, the central domain controller is in master control mode, and the redundant central domain controller is in hot backup mode. The autonomous driving controller transmits vehicle control commands to the central domain controller via the autonomous driving main CAN bus, and the central domain controller sends the vehicle control commands to the chassis actuators via the power main CAN bus. The redundant central domain controller monitors and backs up the entire network communication data in real time through the autonomous driving auxiliary CAN bus and the power auxiliary CAN bus, and does not participate in normal command transmission. When the central domain controller, the autonomous driving main CAN bus, or the power main CAN bus fails, the redundant central domain controller switches from hot backup mode to master control mode, receives the vehicle control commands from the autonomous driving controller via the autonomous driving auxiliary CAN bus, and forwards the vehicle control commands to the chassis actuators via the power auxiliary CAN bus. This ensures that the system can tolerate any single point of failure in the power supply, power distribution, controller, or communication link, and continues to perform safety functions after a failure occurs, meeting the highest level of functional safety requirements. Even under extreme combinations of failures, the system can still receive parking commands via backup paths or execute preset safety strategies to achieve smooth and controllable braking and stop, avoiding out-of-control collisions. This provides a crucial safety safeguard for the large-scale, unmanned operation of autonomous logistics vehicles in complex environments such as open roads and industrial parks, reducing safety risks and liability concerns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122607250A_ABST
    Figure CN122607250A_ABST
Patent Text Reader

Abstract

The application provides an unmanned vehicle control system, which comprises a power supply redundancy subsystem; the power supply redundancy subsystem comprises: a main power supply; an auxiliary power supply; a chassis actuator, which is electrically connected with the auxiliary power supply; a central domain controller, which is electrically connected with the main power supply and is electrically connected with the chassis actuator through a first power distribution circuit and a second power distribution circuit respectively, and is used for controlling the power supply path of the chassis actuator; in a normal power distribution mode, the central domain controller controls the main power supply to supply power to the chassis actuator through the first power distribution circuit; in a first-level redundant power distribution mode, the central domain controller controls the main power supply to supply power to the chassis actuator through the second power distribution circuit; and in a second-level redundant power distribution mode, the auxiliary power supply supplies power to the chassis actuator. The application solves the problem that a single power supply failure of a traditional unmanned vehicle directly leads to complete or partial loss of control of braking by an automatic driving system, and the vehicle enters an uncontrollable state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of autonomous vehicle technology, and in particular to an autonomous vehicle control system. Background Technology

[0002] In existing driverless vehicles, especially logistics vehicles and work vehicles, steering and braking systems are the core actuators that ensure driving safety.

[0003] In current electrical architecture solutions, the power supply scheme uses a single battery to power the vehicle controller and chassis actuators (such as EPS and TwoBox). The communication scheme typically uses a single-channel or non-heterogeneous redundant CAN bus for communication between the autonomous driving controller and the vehicle controller, as well as between the vehicle controller and the steering and braking controllers. When any communication link experiences a permanent or intermittent failure, the autonomous driving system will lose effective control over the vehicle's steering and braking, relying only on limited low-level safety strategies and unable to achieve conditional continuous safe driving or active braking.

[0004] The aforementioned technical solutions, whether in the power supply circuit or the communication link, all have single points of failure. A single fault, such as a main battery failure, a main power supply line open circuit, a main CAN bus short circuit, or a controller communication interface failure, will directly cause the autonomous driving system to completely or partially lose control of steering and braking, and the vehicle will immediately enter an uncontrollable state. This fails to meet the safety requirements of high-level autonomous driving: For Level 4 autonomous driving, the system is required to maintain a minimum risk state or safely stop after any single point of failure or even some multi-point failures. Summary of the Invention

[0005] This invention provides a control system for unmanned vehicles. By setting up a power supply redundancy subsystem and a communication redundancy subsystem, it solves the problem that a single failure in a traditional unmanned vehicle will directly lead to the complete or partial loss of braking control by the autonomous driving system, causing the vehicle to enter an uncontrollable state.

[0006] In a first aspect, an embodiment of the present invention provides an unmanned vehicle control system, including a power supply redundancy subsystem. The power supply redundancy subsystem includes: a main power supply; an auxiliary power supply; a chassis actuator electrically connected to the auxiliary power supply; and a central domain controller electrically connected to the main power supply and electrically connected to the chassis actuator via a first power distribution circuit and a second power distribution circuit, respectively, for controlling the power supply path of the chassis actuator. The power distribution modes of the power supply redundancy subsystem include a normal power distribution mode, a first-level redundancy power distribution mode, and a second-level redundancy power distribution mode. In the normal power distribution mode, the central domain controller controls the main power supply to power the chassis actuator via the first power distribution circuit. In the first-level redundancy power distribution mode, the central domain controller controls the main power supply to power the chassis actuator via the second power distribution circuit. In the second-level redundancy power distribution mode, the auxiliary power supply powers the chassis actuator. When the first power distribution circuit is in an abnormal state, the power supply redundancy subsystem switches to the first-level redundancy power distribution mode. When the second power distribution circuit or the central domain controller is in an abnormal state, the power supply redundancy subsystem switches to the second-level redundancy power distribution mode.

[0007] Optional features also include a redundant central domain controller, an autonomous driving controller, an autonomous driving main CAN bus, a power main CAN bus, an autonomous driving auxiliary CAN bus, and a power auxiliary CAN bus. The chassis actuator is also used to acquire vehicle status information; The autonomous driving controller is used to generate and output vehicle control commands, and to receive vehicle status information to adjust the vehicle control commands. The autonomous driving main CAN bus is electrically connected to the autonomous driving controller and the central domain controller respectively. It is used to transmit vehicle control commands from the autonomous driving controller to the central domain controller, and to feed back vehicle status information from the central domain controller to the autonomous driving controller. The main CAN bus is electrically connected to the central domain controller and the chassis actuators respectively. It is used to transmit vehicle control commands verified by the central domain controller to the chassis actuators, and to transmit vehicle status information collected by the chassis actuators back to the central domain controller. The autonomous driving auxiliary CAN bus is electrically connected to the autonomous driving controller and the redundant central domain controller respectively. The autonomous driving main CAN bus and the autonomous driving auxiliary CAN bus are redundant backups of each other. The auxiliary CAN bus is electrically connected to the redundant central domain controller and the chassis actuator, and the main CAN bus and the auxiliary CAN bus are redundant backups of each other. The communication modes of the autonomous vehicle control system include normal mode; In normal mode, vehicle control commands are transmitted from the autonomous driving controller to the central domain controller via the autonomous driving main CAN bus, and after verification, are transmitted to the chassis actuators via the powertrain main CAN bus. Vehicle status information is transmitted back from the chassis actuators to the central domain controller via the powertrain main CAN bus, and then transmitted to the autonomous driving controller via the autonomous driving main CAN bus. The redundant central domain controller is used to obtain vehicle control commands via the autonomous driving auxiliary CAN bus and to obtain vehicle status information via the powertrain auxiliary CAN bus. Both the central domain controller and the redundant central domain controller use the vehicle control commands as the expected execution benchmark and the vehicle status information as the actual execution result, and perform independent cross-verification respectively.

[0008] Optionally, the communication mode of the autonomous vehicle control system also includes an autonomous main CAN bus failure mode; the central domain controller and the redundant central domain controller are connected via a first communication link. In the autonomous driving main CAN bus failure mode, the vehicle control commands output by the autonomous driving controller are transmitted to the redundant central domain controller via the autonomous driving auxiliary CAN bus. The redundant central domain controller forwards the vehicle control commands to the central domain controller through the first communication link. After verification, the commands are transmitted to the chassis actuators via the power main CAN bus.

[0009] Optionally, the communication mode of the autonomous vehicle control system also includes a power main CAN bus failure mode; the central domain controller and the redundant central domain controller are connected via a first communication link. In the power main CAN bus failure mode, the vehicle control command verified by the central domain controller is transmitted to the redundant central domain controller through the first communication link. The redundant central domain controller then transmits the vehicle control command to the chassis actuator through the power auxiliary CAN bus.

[0010] Optionally, the communication mode of the autonomous vehicle control system also includes a central domain controller failure mode; In the central domain controller failure mode, the vehicle control commands output by the autonomous driving controller are transmitted to the redundant central domain controller via the autonomous driving auxiliary CAN bus. After the redundant central domain controller verifies the legality of the vehicle control commands, it transmits them to the chassis actuators via the power auxiliary CAN bus.

[0011] Optionally, the central domain controller is used to send vital heartbeat signals to the redundant central domain controller at a preset period. The redundant central domain controller is used to determine that the system enters the central domain controller failure mode when no vital heartbeat signal is received within a preset period, or when the received heartbeat signal is abnormal.

[0012] Optionally, chassis actuators include an electronic steering controller and an electronic brake controller.

[0013] Optionally, the first communication link includes an in-vehicle Ethernet link and an in-vehicle CAN bus; the central domain controller and the redundant central domain controller are connected via at least one of the in-vehicle CAN bus or the in-vehicle Ethernet link.

[0014] Optionally, the central domain controller is also used to generate corresponding drive commands based on the power distribution mode of the power supply redundancy subsystem and the communication mode of the autonomous vehicle control system. Specifically: when the power supply redundancy subsystem enters the primary redundancy power distribution mode or the secondary redundancy power distribution mode, the drive commands include load limiting commands; when the autonomous vehicle control system enters the autonomous main CAN bus fault mode or the power main CAN bus fault mode, the drive commands include speed limiting and degrading commands; when the autonomous vehicle control system enters the central domain controller fault mode, the drive commands include pull-over commands.

[0015] Optionally, the central domain controller is also used to send drive commands, including parking wait commands, when it detects that both the autonomous main CAN bus and the autonomous auxiliary CAN bus have entered a fault state, or when both the power main CAN bus and the power auxiliary CAN bus have entered a fault state.

[0016] This invention provides an autonomous vehicle control system, including a power supply redundancy subsystem and an autonomous vehicle control system. The power supply redundancy subsystem includes a main power supply and an auxiliary power supply. The main power supply is electrically connected to the chassis actuators via a first power distribution circuit and a second power distribution circuit. The auxiliary power supply is directly electrically connected to the chassis actuators. The power distribution modes of the power supply redundancy subsystem include a normal power distribution mode, a first-level redundancy power distribution mode, and a second-level redundancy power distribution mode. Through these three-level power distribution modes, it is ensured that the chassis actuators can still obtain necessary power when a single power supply path or the central domain controller fails, thereby avoiding vehicle loss of control due to power outages. The autonomous vehicle control system achieves communication redundancy through three independent communication paths. Each bus and link uses independent wiring harnesses and hardware interfaces to achieve physical-level fault isolation. Under normal operating conditions, the central domain controller is in master control mode, and the redundant central domain controller is in hot backup mode. The autonomous driving controller transmits vehicle control commands to the central domain controller via the autonomous driving main CAN bus, and the central domain controller sends the vehicle control commands to the chassis actuators via the power main CAN bus. The redundant central domain controller monitors and backs up the entire network communication data in real time through the autonomous driving auxiliary CAN bus and the power auxiliary CAN bus, and does not participate in normal command transmission. When the central domain controller, the autonomous driving main CAN bus, or the power main CAN bus fails, the redundant central domain controller switches from hot backup mode to master control mode, receives the vehicle control commands from the autonomous driving controller via the autonomous driving auxiliary CAN bus, and forwards the vehicle control commands to the chassis actuators via the power auxiliary CAN bus. This ensures that the system can tolerate any single point of failure in the power supply, power distribution, controller, or communication link, and continues to perform safety functions after a failure occurs, meeting the highest level of functional safety requirements. Even under extreme combinations of failures, the system can still receive parking commands via backup paths or execute preset safety strategies to achieve smooth and controllable braking and stop, avoiding out-of-control collisions. This provides a crucial safety safeguard for the large-scale, unmanned operation of autonomous logistics vehicles in complex environments such as open roads and industrial parks, reducing safety risks and liability concerns. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the power supply redundancy subsystem of an unmanned vehicle control system provided in an embodiment of the present invention; Figure 2 This is a partial structural schematic diagram of an unmanned vehicle control system provided in an embodiment of the present invention. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be fully described below with reference to the accompanying drawings in the embodiments of this invention, through specific implementation methods. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort fall within the protection scope of this invention.

[0019] Figure 1 This is a schematic diagram of the power supply redundancy subsystem of an autonomous vehicle control system provided in an embodiment of the present invention. The autonomous vehicle control system provided in this embodiment can be specifically applied to various types of autonomous vehicles, such as unmanned delivery vehicles, unmanned sanitation vehicles, and autonomous passenger vehicles. This system uses redundancy design to ensure the stability and reliability of the power supply and communication of the autonomous vehicle, avoiding vehicle loss of control due to a single component or link failure, and ensuring the safety and continuity of the autonomous driving process. (Reference) Figure 1 This invention provides an unmanned vehicle control system, including a power supply redundancy subsystem 100. The power supply redundancy subsystem 100 includes: a main power supply 110; an auxiliary power supply 120; a chassis actuator 130 electrically connected to the auxiliary power supply 120; and a central domain controller 1 electrically connected to the main power supply 110 and electrically connected to the chassis actuator 130 via a first power distribution circuit 101 and a second power distribution circuit 102, respectively, for controlling the power supply path of the chassis actuator 130. The power distribution modes of the power supply redundancy subsystem 100 include a normal power distribution mode, a first-level redundancy power distribution mode, and a second-level redundancy power distribution mode. In the normal power distribution mode... In this mode, the central domain controller 1 controls the main power supply 110 to supply power to the chassis actuator 130 through the first power distribution circuit 101; in the first-level redundant power distribution mode, the central domain controller 1 controls the main power supply 110 to supply power to the chassis actuator 130 through the second power distribution circuit 102; in the second-level redundant power distribution mode, the auxiliary power supply 120 supplies power to the chassis actuator 130; wherein, when the first power distribution circuit 101 is in an abnormal state, the power supply redundancy subsystem 100 switches to the first-level redundant power distribution mode; when the second power distribution circuit 102 or the central domain controller 1 is in an abnormal state, the power supply redundancy subsystem 100 switches to the second-level redundant power distribution mode.

[0020] Specifically, in normal power distribution mode, the central domain controller 1 operates normally, the main power supply 110 has sufficient power, and the central domain controller 1 controls the first power distribution circuit 101 to conduct, through which the main power supply 110 supplies power to the chassis actuator 130. When the central domain controller 1 detects an abnormality in the first power distribution circuit 101 (such as abnormal current, voltage drop, or communication timeout), it switches to the first-level redundant power distribution mode: shutting down the first power distribution circuit 101 and enabling the second power distribution circuit 102, with the main power supply 110 continuing to supply power to the chassis actuator 130 via the second power distribution circuit 102. If the central domain controller 1 further detects a failure in the second power distribution circuit 102, or if the central domain controller 1 itself experiences a power supply abnormality or system crash, it switches to the second-level redundant power distribution mode: an auxiliary power supply 120, independent of the main network, directly provides emergency power to the chassis actuator 130, while the chassis actuator 130 typically enters limp mode or performs a safe stop operation.

[0021] This invention provides an unmanned vehicle control system, including a power supply redundancy subsystem. The power supply redundancy subsystem includes a main power supply and an auxiliary power supply. The main power supply is electrically connected to the chassis actuators via a first power distribution circuit and a second power distribution circuit. The auxiliary power supply is directly electrically connected to the chassis actuators. The power distribution modes of the power supply redundancy subsystem include a normal power distribution mode, a first-level redundancy power distribution mode, and a second-level redundancy power distribution mode. Through these three-level power distribution modes, it is ensured that the chassis actuators can still obtain necessary power when a single power supply path or the central domain controller fails, thereby avoiding vehicle loss of control due to power outages.

[0022] In an optional embodiment, the central domain controller 1 is further configured to make a comprehensive decision on whether to trigger a secondary redundancy power distribution mode or a primary redundancy power distribution mode that bypasses the central domain controller 1 based on the following three types of information: First, the central domain controller 1 collects the voltage signals of the main power supply 110 and the auxiliary power supply 120 in real time. If the voltage of the main power supply 110 drops below a preset low voltage threshold (e.g., 14V is normal, below 9V), and the duration exceeds a preset debouncing time (e.g., 100ms), it is determined that the main power supply 110 has insufficient power supply capacity and it is necessary to switch to the secondary redundancy power distribution mode; furthermore, if the voltage of the auxiliary power supply 120 is also below the emergency power supply threshold, it may trigger the lowest safety level alarm (e.g., parking on the side of the road or waiting). In addition, the central domain controller 1 monitors the output current and voltage of its internal first power distribution circuit 101 and second power distribution circuit 102. When a certain circuit experiences an abnormal increase in current or a sudden drop in voltage, the central domain controller 1 will trigger the primary redundancy power distribution mode, shut down the faulty circuit, and switch to another power distribution circuit. Finally, the chassis actuator 130 (such as the electric power steering system EPS or the intelligent braking system TwoBox) provides real-time feedback via CAN messages on whether it is currently being powered normally by the main power supply network. If the central domain controller 1 receives a "power supply invalid" report from the actuator while supplying power to the chassis actuator 130 through the first power distribution circuit 101 or the second power distribution circuit 102, it determines that there is a latent fault in the power distribution circuit. At this time, if the voltages of the main power supply 110 and the auxiliary power supply 120 are both normal, it first attempts to switch to another power distribution circuit; if the actuator still reports power supply invalid after switching, it triggers the secondary redundant power distribution mode. By integrating voltage information, power distribution circuit self-monitoring, and actuator feedback, the central domain controller 1 can more accurately determine the fault level and execute appropriate redundant actions: selecting power distribution circuit switching or emergency power supply, thereby significantly enhancing the robustness and fault diagnosis capability of the power supply redundancy subsystem 100.

[0023] Figure 2 This is a partial structural schematic diagram of an unmanned vehicle control system provided in an embodiment of the present invention, with reference to... Figure 2In an optional embodiment, the autonomous vehicle control system further includes a redundant central domain controller 210, an autonomous driving controller 2, an autonomous driving main CAN bus 220, a powertrain main CAN bus 230, an autonomous driving auxiliary CAN bus 260, and a powertrain auxiliary CAN bus 250; the chassis actuator 130 is also used to acquire vehicle status information; the autonomous driving controller 2 is used to generate and output vehicle control commands, and receive vehicle status information to adjust the vehicle control commands; the autonomous driving main CAN bus 220 is electrically connected to the autonomous driving controller 2 and the central domain controller 1 respectively, and is used to transmit vehicle control commands from the autonomous driving controller 2 to the central domain controller 1, and to feed back vehicle status information from the central domain controller 1 to the autonomous driving controller 2; the powertrain main CAN bus 230 is electrically connected to the central domain controller 1 and the chassis actuator 130 respectively, and is used to transmit vehicle control commands verified by the central domain controller 1 to the chassis actuator 130, and to send back vehicle status information collected by the chassis actuator 130 to the central domain controller 1; the autonomous driving auxiliary CAN bus 260 is connected to the autonomous driving controller 2 and the redundant central domain controller 210 respectively. Electrically connected, the autonomous driving main CAN bus 220 and the autonomous driving auxiliary CAN bus 260 are redundant backups of each other; the power auxiliary CAN bus 250 is electrically connected to the redundant central domain controller 210 and the chassis actuator 130 respectively, and the power main CAN bus 230 and the power auxiliary CAN bus 250 are redundant backups of each other; the communication mode of the autonomous vehicle control system includes a normal mode; in the normal mode, vehicle control commands are transmitted from the autonomous driving controller 2 to the central domain controller 1 via the autonomous driving main CAN bus 220, and after verification, are transmitted to the chassis via the power main CAN bus 230. Actuator 130; Vehicle status information is transmitted from chassis actuator 130 back to central domain controller 1 via power main CAN bus 230, and then transmitted to autonomous driving controller 2 via autonomous driving main CAN bus 220; Redundant central domain controller 210 is used to obtain vehicle control commands via autonomous driving auxiliary CAN bus 260 and obtain vehicle status information via power auxiliary CAN bus 250; Both central domain controller 1 and redundant central domain controller 210 use vehicle control commands as expected execution benchmarks and vehicle status information as actual execution results, and perform independent cross-validation respectively.

[0024] Among them, the self-driving main CAN bus 220, the power main CAN bus 230, the self-driving auxiliary CAN bus 260, the power auxiliary CAN bus 250 and the first communication link 240 each adopt independent wiring harnesses and independent hardware interfaces.

[0025] Specifically, under normal operating conditions, the central domain controller 1 is in master control mode, and the redundant central domain controller 210 is in hot backup mode. The redundant central domain controller 210 monitors and backs up communication data in real time through the autonomous driving auxiliary CAN bus 260 and the power auxiliary CAN bus 250, and does not participate in normal command transmission. In normal mode, vehicle control commands (such as steering angle and braking force requests) generated by the autonomous driving controller 2 are transmitted to the central domain controller 1 through the autonomous driving main CAN bus 220. The central domain controller 1 performs format verification, security verification, and rationality checks on the received control commands. After the verification is passed, the commands are transmitted to the corresponding chassis actuators 130 (such as electronic steering controllers and electronic brake controllers) through the power main CAN bus 230. After the chassis actuators 130 execute the commands, they transmit the actual execution results (i.e., vehicle status information, such as actual steering angle, actual braking pressure, wheel speed, etc.) back to the central domain controller 1 through the power main CAN bus 230, and then the central domain controller 1 transmits them to the autonomous driving controller 2 through the autonomous driving main CAN bus 220, forming a closed-loop control.

[0026] It should be noted that in normal mode, both the central domain controller 1 and the redundant central domain controller 210 continuously monitor the command and status streams on all CAN buses, performing independent cross-checks: the central domain controller 1 compares its issued expected commands with the actual returned status information to determine if the execution deviation is within the allowable range; the redundant central domain controller 210 also monitors command and status data, independently performing command-state consistency checks. Based on their respective independent cross-check results, the central domain controller 1 and the redundant central domain controller 210 collaboratively determine whether the communication link is abnormal, and, if necessary, control the autonomous vehicle control system to switch to the corresponding fault mode. All CAN buses and links use independent wiring harnesses and independent hardware interfaces, ensuring physical-level fault isolation and preventing a single CAN bus failure from affecting the normal communication of other CAN buses.

[0027] It should be noted that the central domain controller 1 and the redundant central domain controller 210 are redundant with each other, and they are identical in hardware configuration and software function; the central domain controller 1 and the redundant central domain controller 210 are only logically distinguished by naming, which are used to describe different roles currently in master control state and hot backup state, and the roles can be interchanged according to the system state switch.

[0028] Optionally, the vehicle status information includes the vehicle status information of the autonomous driving main CAN bus 220, the vehicle status information of the power main CAN bus 230, the vehicle status information of the autonomous driving auxiliary CAN bus 260, and the vehicle status information of the power auxiliary CAN bus 250; the central domain controller 1 is also used to: determine whether the autonomous driving main CAN bus 220 and the power main CAN bus 230 have entered a fault state based on the vehicle status information; and control the autonomous vehicle control system to enter the autonomous driving main CAN bus fault mode when the autonomous driving main CAN bus 220 is faulty; and control the autonomous vehicle control system to enter the power main CAN bus fault mode when the power main CAN bus 230 is faulty.

[0029] Specifically, the vehicle status information includes the real-time operating status of the autonomous driving main CAN bus 220, the power main CAN bus 230, the autonomous driving auxiliary CAN bus 260, and the power auxiliary CAN bus 250. The central domain controller 1, through its integrated CAN controller registers and monitoring tasks, periodically reads diagnostic data such as error counters, frame reception timeouts, and bus off flags for each bus to determine whether the autonomous driving main CAN bus 220 and the power main CAN bus 230 have entered a fault state. When the central domain controller 1 detects a fault in the autonomous driving main CAN bus 220, it sends a mode switching command to the redundant central domain controller 210, controlling the autonomous vehicle control system to enter the autonomous driving main CAN bus fault mode. Similarly, when a similar fault is detected in the power main CAN bus 230, the central domain controller 1 controls the subsystem to enter the power main CAN bus fault mode.

[0030] Optionally, the vehicle status information includes numerical vehicle status information and hardware flag signals; the central domain controller 1 is also used to compare the numerical vehicle status information with the corresponding preset threshold, and determine whether the autonomous main CAN bus 220 and the power main CAN bus 230 have entered a fault state based on the comparison result; and to determine the fault using hardware flag signals; wherein, the numerical vehicle status information includes at least one of bus load rate, error frame count and node message update timeout time; and the hardware flag signals include at least one of node loss flag and bus shutdown status flag.

[0031] Among them, numerical vehicle status information can be understood as bus health indicators that can be measured or statistically quantified; hardware flag signals can be understood as discrete status flag bits directly given by the CAN controller hardware; bus load rate can be understood as the ratio of the actual amount of data transmitted by the CAN bus per unit time to its maximum capacity. An excessively high load rate may lead to message delays or loss; error frame count can be understood as the number of accumulated error frames inside the CAN controller (such as the transmit error counter TEC and receive error counter REC); node message update timeout can be understood as the time interval at which the central domain controller 1 or the autonomous driving controller 2 expects to receive periodic messages from a specific node; node loss flag can be understood as a flag bit actively set by the CAN controller when it detects that a node has not sent any messages for a long time; bus off status flag can be understood as the "BusOff" status flag bit that the CAN controller enters after the transmit error counter (TEC) exceeds 256 times.

[0032] Specifically, the central domain controller 1 periodically collects numerical vehicle status information (such as bus load rate, error frame count, and node message update timeout). It compares these values ​​with corresponding preset thresholds (e.g., bus load rate > 85%, error frame count > 50 times / second, node message update timeout > 100ms, or three consecutive message loss). When any value consistently exceeds the threshold and exceeds the preset debouncing time (e.g., 50ms), the central domain controller 1 determines that the corresponding bus is faulty. In addition, the central domain controller 1 also reads the hardware flag signals of the CAN controller. Once it confirms that the node loss flag is set or the bus off status flag is set, a bus fault is directly determined.

[0033] Optionally, the autonomous vehicle control system also includes a fault mode for the autonomous main CAN bus 220; in the fault mode of the autonomous main CAN bus 220, the vehicle control commands output by the autonomous driving controller 2 are transmitted to the redundant central domain controller 210 via the autonomous auxiliary CAN bus 260, and the redundant central domain controller 210 forwards the vehicle control commands to the central domain controller 1 via the first communication link 240, and after verification, they are transmitted to the chassis actuator 130 via the power main CAN bus 230.

[0034] Specifically, when the central domain controller 1 or the redundant central domain controller 210 detects a fault in the autonomous driving main CAN bus 220 (e.g., continuous failure to receive heartbeat messages from the autonomous driving controller 2, error frame count exceeding the threshold, or the bus entering an off state), it controls the autonomous vehicle control system to switch to the autonomous driving main CAN bus 220 fault mode. In this mode, the autonomous driving controller 2 transmits the generated vehicle control commands (such as target steering angle, target deceleration, etc.) to the redundant central domain controller 210 via the autonomous driving auxiliary CAN bus 260 (a redundant backup bus physically isolated from the autonomous driving main CAN bus 220). After receiving the commands, the redundant central domain controller 210 forwards the vehicle control commands to the central domain controller 1 via the first communication link 240 (a point-to-point dedicated communication link, such as Ethernet or UART). The central domain controller 1 verifies and validates the received control commands, confirming their integrity and legality, and then sends the commands to the corresponding chassis actuators 130 (such as electronic steering controllers and electronic brake controllers) via the power main CAN bus 230. After the chassis actuator 130 executes the command, it transmits the vehicle status information back to the central domain controller 1 via the main power CAN bus 230, and then forwards it to the redundant central domain controller 210 via the first communication link 240. The redundant central domain controller 210 feeds back the status information to the autonomous driving controller 2 via the autonomous driving auxiliary CAN bus 260, thus completing the closed-loop control.

[0035] Optionally, the autonomous vehicle control system further includes a power main CAN bus 230 fault mode; the central domain controller 1 and the redundant central domain controller 210 are connected via a first communication link 240; in the power main CAN bus 230 fault mode, the vehicle control command verified by the central domain controller 1 is transmitted to the redundant central domain controller 210 via the first communication link 240, and the redundant central domain controller 210 transmits the vehicle control command to the chassis actuator 130 via the power auxiliary CAN bus 250.

[0036] Specifically, when the central domain controller 1 or the redundant central domain controller 210 detects a fault in the main power CAN bus 230 (e.g., continuous failure to receive messages from the chassis actuators 130, error frame count exceeding the threshold, or the bus entering an off state), it controls the autonomous vehicle control system to switch to the main power CAN bus 230 fault mode. In this mode, the vehicle control commands generated by the autonomous driving controller 2 are first transmitted to the central domain controller 1 via the autonomous driving main CAN bus 220. The central domain controller 1 verifies and validates the commands, confirming their integrity and legality, and then transmits the verified vehicle control commands to the redundant central domain controller 210 via the first communication link 240 (a point-to-point dedicated communication link, such as Ethernet or UART). After receiving the commands, the redundant central domain controller 210 sends the commands to the corresponding chassis actuators 130 (such as the electronic steering controller and electronic brake controller) via the auxiliary power CAN bus 250 (a redundant backup bus physically isolated from the main power CAN bus 230). After the chassis actuator 130 executes the command, it transmits the vehicle status information back to the redundant central domain controller 210 via the power auxiliary CAN bus 250, and then forwards it to the central domain controller 1 via the first communication link 240. The central domain controller 1 feeds back the status information to the autonomous driving controller 2 via the autonomous driving main CAN bus 220, thus completing the closed-loop control.

[0037] Optionally, the redundant central domain controller 210 and the central domain controller 1 are connected via a first communication link 240; the autonomous vehicle control system also includes a central domain controller failure mode; in the central domain controller failure mode, the autonomous driving controller 2 sends a drive command to the redundant central domain controller 210 via the autonomous driving auxiliary CAN bus 260, and the redundant central domain controller 210 drives the chassis actuator 130 via the power auxiliary CAN bus 250 after verifying the validity of the vehicle control command; wherein, when the central domain controller 1 fails, the autonomous vehicle control system enters the central domain controller failure mode.

[0038] Specifically, redundant central domain controller 210 and central domain controller 1 perform routine health monitoring through the first communication link 240. Redundant central domain controller 210 sends query requests to central domain controller 1 at set intervals (e.g., every 50ms) and monitors whether it responds within a specified timeout period (e.g., three consecutive no-response attempts within 150ms). If no response is received within the timeout period, or if hardware monitoring (e.g., a dedicated reset monitoring pin) detects that central domain controller 1 is in a continuous reset state, a fault is determined in central domain controller 1. At this time, the autonomous vehicle control system immediately enters the central domain controller fault mode. In this mode, the autonomous driving controller 2 sends drive commands (such as steering angle and braking force) to the redundant central domain controller 210 via the autonomous driving auxiliary CAN bus 260. The redundant central domain controller 210 forwards these commands directly to the chassis actuators 130 (such as EPS and TwoBox) via the power auxiliary CAN bus 250 according to the preset safety strategy (such as maintaining the current actuator state or performing limited degradation operations). This ensures that the vehicle's critical actuators can still receive commands through the backup path and perform safety actions such as progressive braking, thus avoiding the risk of vehicle loss of control due to a single point of failure of the central domain controller 1.

[0039] Optionally, the redundant central domain controller 210 is also used to send a life signal to the central domain controller 1 according to a preset period, and control the autonomous vehicle control system to enter the central domain controller failure mode when no feedback instruction is received within the preset feedback period or the feedback instruction is incorrect; the central domain controller 1 is also used to send a feedback instruction to the redundant central domain controller 210 when it receives a life signal.

[0040] Among them, the life signal can be understood as the "heartbeat" or "response" message periodically sent by the redundant central domain controller 210 to the central domain controller 1; the feedback instruction can be understood as the response message (such as acknowledgment code, timestamp or check value) sent back by the central domain controller 1 to the redundant central domain controller 210 after receiving the life signal; the preset feedback period can be understood as the maximum time that the redundant central domain controller 210 waits for the central domain controller 1 to reply.

[0041] Specifically, the redundant central domain controller 210 sends a life signal (e.g., an incrementing sequence number or fixed code) to the central domain controller 1 at a preset period (e.g., 20ms). Upon receiving the life signal during normal operation, the central domain controller 1 should immediately return a feedback instruction to the redundant central domain controller 210 (e.g., an inverted sequence number of the original life signal or a calculated CRC checksum). After sending the life signal, the redundant central domain controller 210 starts a timer. If it does not receive a feedback instruction from the central domain controller 1 within the preset feedback period (e.g., the interval between three consecutive transmission cycles, i.e., 60ms), or if the received feedback instruction is incorrect (e.g., a mismatched sequence number or a checksum error), the redundant central domain controller 210 determines that the central domain controller 1 has entered an abnormal state (software crash, infinite loop, or hardware failure), and then actively controls the autonomous vehicle control system to enter the central domain controller fault mode.

[0042] Optionally, the central domain controller 1 is further configured to send a life signal to the redundant central domain controller 210 according to a preset period, and determine that the redundant central domain controller 210 has failed if no feedback instruction is received from the redundant central domain controller 210 within a preset feedback period, or if the feedback instruction is incorrect; when the redundant central domain controller 210 fails, the autonomous vehicle control system continues to operate in the general state of a non-redundant system, and the central domain controller 1 maintains normal instruction transmission and status feedback through the autonomous driving main CAN bus 220 and the power main CAN bus 230.

[0043] Optionally, the chassis actuator 130 includes an electronic steering controller 131 and an electronic brake controller 132.

[0044] Specifically, the chassis actuator 130 includes an electronic steering controller 131 and an electronic brake controller 132. In the power supply redundancy subsystem 100, the power supply terminals of the electronic steering controller 131 and the electronic brake controller 132 are both connected to the first power distribution circuit 101, the second power distribution circuit 102, and the auxiliary power supply 120.

[0045] Furthermore, in an optional embodiment, the main power CAN bus 230 includes two independent hardware branches: a first branch connects to the electronic steering controller 131, and a second branch connects to the electronic brake controller 132; the auxiliary power CAN bus 250 also includes two independent hardware branches: a third branch connects to the electronic steering controller 131, and a fourth branch connects to the electronic brake controller 132. Each actuator has an independent, isolated physical communication channel on each bus. When a short circuit or transceiver failure occurs in a CAN branch (such as the second branch) of an actuator (such as the electronic brake controller 132), the fault is confined to that branch and will not affect the normal communication of the electronic steering controller 131 connected to another branch (such as the first branch) on the same bus; similarly, the fault will not be propagated across the bus to the corresponding branch (such as the third or fourth branch) of the auxiliary power CAN bus 250. This branch-level isolation design achieves physical isolation between actuators in case of failure of a single actuator or a single branch. This ensures that the remaining actuators can still communicate with the central domain controller 1 or the redundant central domain controller 210 through their own independent intact branches, thereby maintaining the vehicle's basic steering and braking capabilities.

[0046] Optionally, the first communication link 240 includes an in-vehicle Ethernet link and an in-vehicle CAN bus; the central domain controller 1 and the redundant central domain controller 210 are connected via at least one of the in-vehicle CAN bus or the in-vehicle Ethernet link.

[0047] Among them, the vehicle Ethernet link can be understood as a vehicle high-speed network physical link based on the IEEE 802.3 standard (such as 100BASE-T1 or 1000BASE-T1); the vehicle CAN bus can be understood as a conventional CAN or CANFD bus, used to provide a highly reliable and interference-resistant backup or control command transmission channel for communication between the central domain controller 1 and the redundant central domain controller 210.

[0048] Specifically, the first communication link 240 adopts a dual physical media redundancy architecture, including both an in-vehicle Ethernet link and an in-vehicle CAN bus as independent communication media. The central domain controller 1 and the redundant central domain controller 210 can communicate using at least one of these media. Under normal operating conditions, the central domain controller 1 and the redundant central domain controller 210 preferentially exchange monitoring data (such as bus vehicle status information, life signals, etc.) via the in-vehicle Ethernet link in a high-bandwidth, low-latency manner. When the Ethernet link fails (such as disconnection, excessive packet loss rate, or port damage), the central domain controller 1 and the redundant central domain controller 210 can automatically switch to the in-vehicle CAN bus to continue executing critical interactive commands such as heartbeat monitoring and status interrogation, ensuring that the fault judgment logic of the central domain controller 1 is not affected by the failure of a single communication link.

[0049] Optionally, the central domain controller 1 is also used to generate corresponding drive commands based on the power distribution mode of the power supply redundancy subsystem 100 and the communication mode of the autonomous vehicle control system, wherein: when the power supply redundancy subsystem 100 enters the primary redundancy power distribution mode or the secondary redundancy power distribution mode, the drive commands include load limiting commands; when the autonomous vehicle control system enters the autonomous main CAN bus fault mode or the power main CAN bus fault mode, the drive commands include speed limiting and degrading commands; when the autonomous vehicle control system enters the central domain controller fault mode, the drive commands include pull-over commands.

[0050] Among them, the load limiting instruction can be understood as an instruction to reduce the power demand of the chassis actuator 30 (such as limiting the maximum current of the steering motor or reducing the duty cycle of the brake pump); the speed limit downgrade instruction can be understood as an instruction to limit the maximum speed of the vehicle (such as forcibly limiting the speed to 30km / h or gradually reducing it to a safe speed); the pull-over instruction can be understood as a safety instruction that requires the vehicle to autonomously drive to the side of the road and park safely.

[0051] Specifically, the central domain controller 1 generates corresponding drive commands based on the current power distribution mode of the power supply redundancy subsystem 100 and the current communication mode of the autonomous vehicle control system. When the power supply redundancy subsystem 100 enters a first-level redundancy power distribution mode (the main power supply 110 supplies power through the second power distribution circuit 102) or a second-level redundancy power distribution mode (the auxiliary power supply 120 supplies power directly), the central domain controller 1 determines that the power supply capacity has decreased or that there is a hidden danger in the power distribution circuit. At this time, the drive commands transmitted include load limiting commands, which limit the assist power of the electronic steering controller 131 and the pump current of the electronic brake controller 132 to avoid power supply voltage collapse due to instantaneous high current demand. When the autonomous vehicle control system enters the autonomous driving main CAN bus fault mode or the power main CAN bus fault mode, the central domain controller 1 determines that the communication real-time performance or redundancy has decreased. At this time, the drive commands transmitted include speed limit and downgrade commands, which actively limit the maximum operating speed of the vehicle to a preset safety value (such as 30 km / h) to reduce the dependence on high-speed, high-density communication. When the autonomous vehicle control system enters the central domain controller failure mode, the central domain controller 1 has failed. This instruction is directly generated and transmitted by the redundant central domain controller 210 according to the preset safety strategy: regardless of the current vehicle speed and position, the instruction to pull over is executed, and the electronic steering controller 131 and the electronic brake controller 132 are controlled to work together to complete lane changing, deceleration, stopping and parking operations to achieve the minimum risk state.

[0052] Optionally, the central domain controller 1 is also used to issue drive commands, including parking wait commands, when it detects that both the autonomous main CAN bus 220 and the autonomous auxiliary CAN bus 260 have entered a fault state, or when both the power main CAN bus 230 and the power auxiliary CAN bus 250 have entered a fault state. (This also applies to the controller and electronic brake controller.)

[0053] Among them, the parking wait instruction can be understood as an emergency braking instruction that requires the vehicle to stop immediately and remain stationary.

[0054] Specifically, when the central domain controller 1 detects a complete bus failure meeting any of the following conditions, it determines that the vehicle can no longer reliably receive or forward drive commands through any CAN bus channel: both the autonomous driving main CAN bus 220 and the autonomous driving auxiliary CAN bus 260 are in a fault state (i.e., communication with the autonomous driving controller 2 is completely interrupted); both the power main CAN bus 230 and the power auxiliary CAN bus 250 are in a fault state (i.e., communication with the electronic steering controller 131 and the electronic brake controller 132 is completely interrupted). At this time, the central domain controller 1 generates and transmits a parking wait command. After the vehicle comes to a complete stop, the electronic brake controller 132 maintains the braking pressure or switches to the parking lock state to ensure that even in the extreme case of complete failure of the main and auxiliary communication buses, the vehicle can still perform controllable emergency braking and remain stationary, preventing loss of control and rolling.

[0055] It should be noted that in the autonomous vehicle control system provided in this application, the autonomous driving controller 2, as the intelligent driving decision layer, is responsible for outputting lateral and longitudinal driving requirements and vehicle control intentions; the central domain controller 1 and the redundant central domain controller 210 constitute a dual-controller parallel verification architecture, which is redundant and interchangeable, jointly undertaking the responsibilities of whole-vehicle signal acquisition, fault arbitration, and whole-vehicle safety degradation intervention; under normal operating conditions, one domain controller acts as the main control channel execution scheduler, responsible for receiving instructions from the autonomous driving controller 2 and sending them to the steering and braking actuators to complete the underlying chassis closed-loop control, while the other domain controller acts as a hot backup node to monitor and verify the entire network communication data in real time; when the main control channel fails, the hot backup node seamlessly takes over the instruction forwarding function to ensure uninterrupted vehicle control. The electronic steering controller 131 acts as the vehicle's lateral actuator, and the electronic brake controller 132 acts as the brake-by-wire integrated unit, responsible for the vehicle's longitudinal acceleration, deceleration, and braking execution. In the four-channel CAN bus link division, the autonomous driving main CAN bus 220 serves as the main control uplink bus, transmitting autonomous driving control requests and real-time chassis status. It is positioned as the main control path for autonomous driving, and all active vehicle control commands must pass through this link. The first-level command validity verification is completed by the central domain controller 1. The power main CAN bus 230 serves as the main control downlink execution bus, sending verified commands to the actuators and receiving real-time output torque, braking pressure, and hardware faults from the actuators, forming a real-time closed-loop control of the chassis, with the highest real-time priority. The autonomous driving auxiliary CAN bus 260 serves as the redundant monitoring uplink bus, synchronously transmitting complete driving decision intentions and warning information to the redundant central domain controller 210, and is physically isolated from the autonomous driving main CAN bus 220. The power auxiliary CAN bus 250 serves as the redundant status acquisition bus, enabling the actuators to directly upload raw execution data and hardware faults to the redundant central domain controller 210 without going through the central domain controller 1.

[0056] The redundant central domain controller 210 operates as a dual-redundant controller with the following overall mechanism: In terms of hierarchical architecture, the main control link is "Autonomous Driving Controller 2 → Autonomous Driving Main CAN Bus 220 → Central Domain Controller 1 → Power Main CAN Bus 230 → Chassis Actuator 130," and the redundant monitoring link is "Autonomous Driving Controller 2 → Autonomous Driving Auxiliary CAN Bus 260 → Redundant Central Domain Controller 210 → Power Auxiliary CAN Bus 250 → Chassis Actuator 130." The two links and their transceiver channels are completely independent, with no co-linear interference, thus avoiding safety and control failures caused by a single link failure. Under normal operating conditions, the autonomous driving controller 2 generates the same set of driving intentions and synchronously distributes them to the two independent buses: the main path sends the intentions to the central domain controller 1 via the autonomous driving main CAN bus 220, and after verification and compliance, drives the actuators via the power main CAN bus 230; the redundant path synchronously sends the intentions to the redundant central domain controller 210 via the autonomous driving auxiliary CAN bus 260, recording the expected actions as a verification benchmark. The actuator synchronously outputs two execution status feedback channels: the main feedback is transmitted back to the central domain controller 1 via the main power CAN bus 230 to complete the main control closed loop, and the redundant feedback is directly connected to the redundant central domain controller 210 via the auxiliary power CAN bus 250 to upload the actual execution result. The redundant central domain controller 210 compares the expected action received from the autonomous driving auxiliary CAN bus 260 with the actual execution result received from the auxiliary power CAN bus 250. If the data matches, it determines that there is no abnormality in the system and synchronizes the vehicle status; if the data mismatches or there is a deviation, it determines that there is a risk of failure in the main control link and issues a full-domain safety policy (audio-visual alarm, forced exit from autonomous driving, request for deceleration and braking, and reminder to the driver to take over) with the vehicle monitoring authority.

[0057] In the fault redundancy fallback scenario, when the main control link fails (the autonomous driving main CAN bus 220 is disconnected or the central domain controller 1 fails), the redundant central domain controller 210 continuously receives decision intentions through the autonomous driving auxiliary CAN bus 260, and at the same time reads the status of the chassis actuators in real time through the power auxiliary CAN bus 250, quickly identifies the main channel disconnection and actively issues vehicle degradation commands and full-domain fault alarms; when the redundant monitoring link fails, the main control link is still fully available, only the redundancy verification capability of the redundant central domain controller 210 is lost, the system is degraded to single-channel operation but the basic intelligent driving functions are not restricted; when the chassis actuator 130 has a hardware failure, the actuator reports the fault synchronously through both channels, the central domain controller 1 immediately cuts off the control command output, and the redundant central domain controller 210 synchronously pushes the fault reminder to the interactive device, realizing dual-channel redundant fault reporting.

[0058] The advantages of the redundant central domain controller 210 as a dual-redundant controller are as follows: as a vehicle-level monitoring unit, it has the authority to coordinate signals from the intelligent driving system, chassis, and body, with redundancy verification covering the entire vehicle dimension; the main control bus and redundant monitoring bus have independent wiring and independent transceivers, ensuring that short circuits or electromagnetic interference on a single bus will not be transmitted to the other channel, meeting ASIL-D functional safety isolation design requirements; the central domain controller 1 completes the first-level instruction validity verification, while the redundant central domain controller 210 independently completes the second-level "decision intent-actual execution" consistency verification, and the independent operation of the two controllers significantly reduces the risk of logic failure of a single controller; a redundant link failure only results in the loss of monitoring functions, while a main link failure is handled by the redundant central domain controller 210, which performs alarm and degradation control as a fallback, eliminating the risk of single-point paralysis; after the redundant central domain controller 210 verifies an anomaly, it can directly issue fault and degradation commands to the instrument panel, body, and vehicle gateway, resulting in faster risk warning and safety intervention response speeds.

[0059] Taking high-speed NOA automatic lane change as an example: the automatic driving controller 2 outputs the lane change driving intention and distributes it synchronously in two ways (autonomous driving main CAN bus 220 → central domain controller 1, autonomous driving auxiliary CAN bus 260 → redundant central domain controller 210); after the central domain controller 1 verifies that the instruction is compliant, it sends the steering torque to the electronic steering controller 131 and the speed adjustment instruction to the electronic brake controller 132 via the power main CAN bus 230 to execute the lane change; the actuators provide synchronous feedback on the two-way status (the power main CAN bus 230 sends back to the central domain controller 1 to complete the main closed loop, and the power auxiliary CAN bus 250 directly transmits to the redundant central domain controller 210 as a redundant verification data source), forming a complete dual-channel parallel monitoring and verification closed loop.

[0060] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, combinations, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A control system for an unmanned vehicle, characterized in that, Including a power supply redundancy subsystem; The power supply redundancy subsystem includes: Main power supply; Auxiliary power supply; The chassis actuator is electrically connected to the auxiliary power supply. The central domain controller is electrically connected to the main power supply and is electrically connected to the chassis actuator through the first power distribution circuit and the second power distribution circuit, respectively, for controlling the power supply path of the chassis actuator; The power distribution modes of the power supply redundancy subsystem include normal power distribution mode, primary redundancy power distribution mode, and secondary redundancy power distribution mode. In the normal power distribution mode, the central domain controller controls the main power supply to supply power to the chassis actuator through the first power distribution circuit; In the first-level redundant power distribution mode, the central domain controller controls the main power supply to power the chassis actuators through the second power distribution circuit: In the two-level redundant power distribution mode, the auxiliary power supply supplies power to the chassis actuator; Specifically, when the first power distribution circuit is in an abnormal state, the power supply redundancy subsystem switches to the first-level redundancy power distribution mode; when the second power distribution circuit or the central domain controller is in an abnormal state, the power supply redundancy subsystem switches to the second-level redundancy power distribution mode.

2. The unmanned vehicle control system according to claim 1, characterized in that, It also includes a redundant central domain controller, an autonomous driving controller, an autonomous driving main CAN bus, a power main CAN bus, an autonomous driving auxiliary CAN bus, and a power auxiliary CAN bus; The chassis actuator is also used to acquire vehicle status information; The autonomous driving controller is used to generate and output vehicle control commands, and to receive the vehicle status information to adjust the vehicle control commands. The autonomous driving main CAN bus is electrically connected to the autonomous driving controller and the central domain controller, respectively, and is used to transmit the vehicle control commands from the autonomous driving controller to the central domain controller, and to feed back the vehicle status information from the central domain controller to the autonomous driving controller. The main CAN bus is electrically connected to the central domain controller and the chassis actuator, respectively, and is used to transmit vehicle control commands verified by the central domain controller to the chassis actuator, and to transmit vehicle status information collected by the chassis actuator back to the central domain controller. The autonomous driving auxiliary CAN bus is electrically connected to the autonomous driving controller and the redundant central domain controller respectively, and the autonomous driving main CAN bus and the autonomous driving auxiliary CAN bus are redundant backups of each other; The auxiliary power CAN bus is electrically connected to the redundant central domain controller and the chassis actuator respectively, and the main power CAN bus and the auxiliary power CAN bus are redundant backups of each other; The communication modes of the unmanned vehicle control system include a normal mode; In the normal mode, the vehicle control command is transmitted from the autonomous driving controller to the central domain controller via the autonomous driving main CAN bus, and after verification, it is transmitted to the chassis actuator via the power main CAN bus. The vehicle status information is transmitted from the chassis actuator to the central domain controller via the main power CAN bus, and then to the autonomous driving controller via the autonomous driving main CAN bus. The redundant central domain controller is used to obtain the vehicle control command via the autonomous driving auxiliary CAN bus and the vehicle status information via the main power CAN bus. Both the central domain controller and the redundant central domain controller use the vehicle control command as the expected execution benchmark and the vehicle status information as the actual execution result, and perform independent cross-validation respectively.

3. The unmanned vehicle control system according to claim 2, characterized in that, The communication mode of the unmanned vehicle control system also includes an autonomous main CAN bus failure mode; the central domain controller and the redundant central domain controller are connected via a first communication link. In the autonomous driving main CAN bus failure mode, the vehicle control command output by the autonomous driving controller is transmitted to the redundant central domain controller via the autonomous driving auxiliary CAN bus. The redundant central domain controller forwards the vehicle control command to the central domain controller through the first communication link. After verification, the command is transmitted to the chassis actuator via the power main CAN bus.

4. The unmanned vehicle control system according to claim 2, characterized in that, The communication mode of the unmanned vehicle control system also includes a power main CAN bus failure mode; the central domain controller and the redundant central domain controller are connected via a first communication link. In the power main CAN bus failure mode, the vehicle control command verified by the central domain controller is transmitted to the redundant central domain controller through the first communication link. The redundant central domain controller then transmits the vehicle control command to the chassis actuator through the power auxiliary CAN bus.

5. The unmanned vehicle control system according to claim 2, characterized in that, The communication modes of the CAN bus communication redundancy subsystem also include the central domain controller failure mode. In the central domain controller failure mode, the vehicle control commands output by the autonomous driving controller are transmitted to the redundant central domain controller via the autonomous driving auxiliary CAN bus. After the redundant central domain controller verifies the validity of the vehicle control commands, it transmits them to the chassis actuator via the power auxiliary CAN bus.

6. The unmanned vehicle control system according to claim 5, characterized in that, The central domain controller is used to send a vital heartbeat signal to the redundant central domain controller at a preset period. The redundant central domain controller is used to determine that the system enters the central domain controller failure mode when it does not receive the vital heartbeat signal within a preset period, or when the received heartbeat signal is abnormal.

7. The unmanned vehicle control system according to claim 1, characterized in that, The chassis actuators include an electronic steering controller and an electronic brake controller.

8. The unmanned vehicle control system according to claim 2, characterized in that, The first communication link includes an in-vehicle Ethernet link and an in-vehicle CAN bus; The central domain controller and the redundant central domain controller are connected via at least one of the vehicle CAN bus or the vehicle Ethernet link.

9. The unmanned vehicle control system according to claim 2, characterized in that, The central domain controller is also used to generate corresponding drive commands based on the power distribution mode of the power supply redundancy subsystem and the communication mode of the autonomous vehicle control system, wherein: When the power supply redundancy subsystem enters the primary redundancy power distribution mode or the secondary redundancy power distribution mode, the drive command includes a load limiting command; When the autonomous vehicle control system enters the autonomous main CAN bus fault mode or the power main CAN bus fault mode, the drive command includes a speed limit and downgrade command. When the autonomous vehicle control system enters the central domain controller failure mode, the driving commands include a pull-to-the-side parking command.

10. The unmanned vehicle control system according to claim 9, characterized in that, The central domain controller is also used to detect when both the autonomous main CAN bus and the autonomous auxiliary CAN bus have entered a fault state, or When both the main power CAN bus and the auxiliary power CAN bus enter a fault state, the drive command includes a parking wait command.