A dual-mode flying car end global safety automatic driving system

CN122756271APending Publication Date: 2026-09-15IAT AUTOMOBILE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610845370.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-11
Publication Date
2026-09-15

AI Technical Summary

Technical Problem

[0004](1)系统架构割裂,双模态管控存在盲区:现有方案多为车载陆行自动驾驶系统与无人机飞控系统的简单拼接,未实现全域融合,陆行-飞行过渡模式(起飞/降落)的管控断层,模式切换过程无闭环安全校验,易引发失控风险

Benefits of technology

[0036] (1) This invention realizes the full-domain fusion autonomous driving of land and air dual modes, breaks the architectural defects of existing system splicing, and realizes seamless autonomous driving of land-air-land through unified perception fusion, decision planning and full-process safety control. There are no blind spots in the mode switching process, which greatly improves the continuity and stability of autonomous driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122756271A_ABST
    Figure CN122756271A_ABST
Patent Text Reader

Abstract

The application discloses a kind of dual-mode flying car end global safety automatic driving system, including core function domain, the core function domain includes perception fusion domain, dual-mode decision planning domain, global safety management and control domain, execution control domain, air-ground collaborative communication domain, redundancy backup domain, the application realizes land-air dual-mode global fusion automatic driving, substantially improve the continuity and stability of automatic driving, construct car end global safety management and control system, fundamentally solve the core safety pain point of flying car, system reliability meets manned aviation level safety requirement, establish full-scene grading emergency disposal mechanism, for different risk levels of failure and sudden scene, realize the full closed-loop emergency disposal from fault correction to safe bottom, maximize guarantee passenger life safety in extreme scene, multi-source heterogeneous perception system is simultaneously adapted land and flying dual scene, effectively reduce the rate of missed detection, false detection, adapt all-weather, full-scene operation demand.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of flying car technology, and in particular to a dual-mode flying car end-to-end safety automatic driving system. Background Technology

[0002] With the development of the low-altitude economy, flying cars have become the core carrier of urban three-dimensional transportation. With the gradual opening of low-altitude airspace, many flying cars have emerged, such as XPeng Huitian flying cars and Chery flying cars. However, most flying cars currently adopt a split design, with the flying part carrying the aerial flight mission and the vehicle end carrying the land driving mission.

[0003] Existing split-type flying cars suffer from the following core flaws, which severely restrict their commercialization:

[0004] (1) Fragmented system architecture and blind spots in dual-modal control: Existing solutions are mostly simple splicing of vehicle-mounted autonomous driving system and UAV flight control system, without achieving full-domain integration. There is a control gap in the transition mode (take-off / landing) between land and flight. There is no closed-loop safety verification during the mode switching process, which can easily lead to loss of control risk.

[0005] (2) Fragmented safety system with no full-link control capability: Existing safety designs are scattered in independent units such as power, flight control, and vehicle, and have not formed a full-domain vehicle-side safety control that runs through the entire link of perception-decision-execution. It is impossible to achieve full-process protection of pre-instruction verification, real-time monitoring during the event, and post-event emergency closed loop.

[0006] (3) Insufficient redundancy design and reliability cannot meet the requirements for manned operation: The key system only adopts simple dual backup and does not design a three-level redundancy architecture of "main-backup-emergency" for the dual land and air scenarios of flying cars. There is a risk of common mode failure of software and hardware, and the failure of a single component can easily lead to systemic accidents.

[0007] (4) Lack of emergency response capabilities and no safety net for extreme scenarios: For fatal scenarios such as in-flight power failure, sudden low-altitude obstacles, and communication interruption, the existing system cannot coordinate with the land and flight systems to complete the entire process of emergency response. There is no graded emergency strategy, and the safety of passengers cannot be effectively guaranteed.

[0008] (5) Poor adaptability of the perception system and insufficient robustness in dual scenarios: It cannot simultaneously take into account both short-range road perception for land travel and long-range low-altitude all-domain perception for flight. The spatiotemporal synchronization accuracy of multi-source data is low. The rate of missed detection and false detection is high in complex urban low-altitude environments, resulting in insufficient stability of autonomous driving. Summary of the Invention

[0009] The purpose of this invention is to overcome the shortcomings of the prior art and provide a dual-modal flying car vehicle-side full-domain safety autonomous driving system, which realizes seamless autonomous driving in all land and air scenarios, full-link full-domain safety management and control, three-level redundancy fault tolerance, and graded emergency closed-loop handling, thereby fundamentally improving the autonomous driving capability and safety protection level of the flying car vehicle-side.

[0010] To achieve the above objectives, the present invention is implemented through the following technical solution:

[0011] A dual-modal flying car vehicle-side all-domain safety autonomous driving system includes core functional domains, which include a perception fusion domain, a dual-modal decision planning domain, an all-domain safety management and control domain, an execution control domain, an air-ground cooperative communication domain, and a redundancy backup domain.

[0012] The perception fusion domain is used to collect multi-source heterogeneous perception data under various operating modes of the dual-modal flying car. Then, the multi-source heterogeneous perception data is fused and processed to output a unified and accurate global environment model and vehicle full-state data, providing reliable data support for decision-making and planning in the dual-modal decision-making and planning domain and safety management in the global safety management and control domain.

[0013] The dual-modal decision planning domain is used to complete the full-process mode management, global path planning, behavior decision-making and local trajectory planning of land mode, flight mode and transition mode based on the global environment model and vehicle full state data output by the perception fusion domain, and generate mode switching instructions and control instructions.

[0014] The full-domain security management domain is used to perform full-dimensional security verification on the control commands generated by the dual-modal decision planning domain, perform real-time diagnosis and classification of hardware and software faults in the entire system, execute fault-tolerant control and graded emergency response strategies, and perform real-time monitoring, health assessment and seamless primary / backup switching management of the core functional domain.

[0015] The execution control domain is used to receive compliant control instructions issued by the global security control domain, complete the execution of actions in land mode, take-off and landing taxiing mode, flight mode, transition mode, and emergency scenarios, and feed back the execution status to the global security control domain in real time.

[0016] The air-ground collaborative communication domain is used to enable two-way communication between the vehicle and the ground control platform, airspace control system, other aircraft and ground transportation facilities, and to simultaneously report vehicle status, receive control instructions and share traffic situation data.

[0017] The redundant backup domain serves as the core of safety redundancy for the entire autonomous driving system. It is used to monitor the health status of the core functional domain and itself in real time. When an abnormal failure is detected in the core functional domain, the redundant backup domain can quickly activate its internal redundant units or emergency units to take over the work of the corresponding domain.

[0018] As a preferred option, multi-source heterogeneous sensing data includes environmental state sensing data, vehicle state sensing data, flight state sensing data, full system hardware state data, full system power state data, and full system safety state data.

[0019] As a preferred approach, the overall security control domain interacts with the perception fusion domain, the dual-modal decision-making and planning domain, the execution control domain, the air-to-ground collaborative communication domain, and the redundancy backup domain. Specifically, it sends self-test commands and fault diagnosis trigger signals to the perception fusion domain and receives feedback from the perception fusion domain on the health status of the perception system and sensor fault information for fault-tolerant control and graded handling. It also sends mode switching authorization or denial commands, emergency path correction commands, system readiness signals, or termination signals to the dual-modal decision-making and planning domain and receives synchronized path planning results, mode switching requests, and decision logic status from the dual-modal decision-making and planning domain for security compliance verification. Verification; sending emergency execution commands and primary / backup switchover commands to the execution control domain, and receiving feedback from the execution control domain on the health status of execution units and actuator fault information to support fault diagnosis and emergency response; sending vehicle fault status, emergency alarm signals, and positioning data to the air-to-ground cooperative communication domain, and receiving feedback from the air-to-ground cooperative communication domain on ground control commands, airspace status, and vehicle-road cooperative information to support emergency decision-making and route compliance verification; sending primary / backup switchover commands and redundant unit activation commands to the redundant backup domain, and receiving feedback from the redundant backup domain on the health status of redundant systems and primary / backup link switchover status to support monitoring and management of the entire domain safety control domain.

[0020] Preferably, the perception fusion domain includes a land perception unit, a flight perception unit, a global state perception unit, and a multi-source heterogeneous fusion processing unit. The land perception unit is used to collect environmental state perception data and vehicle state perception data during land travel and takeoff / landing phases. The land perception unit includes a forward-looking binocular camera, a four-way surround-view fisheye camera, a forward-facing millimeter-wave radar, an angular millimeter-wave radar, an ultrasonic radar, and a lidar. The flight perception unit is used to collect low-altitude environmental state perception data and flight state perception data during flight and transition modes. The flight perception unit includes a 360° solid-state lidar, a long-range infrared camera, a low-altitude meteorological sensor, a barometric altimeter, a GNSS and INS integrated navigation unit, and differential BeiDou. The system includes a positioning module, an ADS-B airborne transponder, and a global state perception unit for collecting hardware status data, power status data, and safety status data for the entire system. This global state perception unit comprises land propulsion system status sensors, flight propulsion system status sensors, a BMS battery management system, a flight control status monitoring unit, braking status sensors, control surface status sensors, rotor actuator status sensors, door safety sensors, seatbelt safety sensors, and emergency equipment cabin safety sensors. The multi-source heterogeneous fusion processing unit adopts an automotive-grade and aerospace-grade dual-chip heterogeneous architecture to fuse and process multi-source heterogeneous perception data, outputting a unified and accurate global environment model and vehicle full-state data.

[0021] As a preferred approach, the fusion processing specifically includes spatiotemporal synchronization of multi-source heterogeneous sensing data, target association matching, three-dimensional modeling of the entire environment, and real-time estimation of the vehicle's full state, in order to eliminate the time difference and spatial position deviation between multiple types of sensing data.

[0022] Preferably, the bimodal decision-making and planning domain includes a mode management unit, a global path planning unit, a behavior decision-making unit, and a local trajectory planning unit.

[0023] The mode management unit is used to identify the status of land mode, flight mode, and transition mode, define mode boundary conditions, judge switching trigger logic, authorize switching and control the entire switching process, and generate corresponding mode switching instructions.

[0024] The global path planning unit is used to integrate land traffic maps, low-altitude airspace maps, user destinations, airspace control requirements, and real-time traffic conditions to generate a global path plan for the entire land-air-land link.

[0025] The behavior decision unit is used to generate behavior decisions that comply with traffic rules and airspace control requirements based on the global environment model and the land-air-land full-link global path planning. The behavior decisions include following other vehicles on land, changing lanes on land, braking on land, climbing in flight, cruising in flight, avoiding obstacles in flight, taking off in transition mode, hovering in transition mode, and landing in transition mode.

[0026] The local trajectory planning unit is used to generate real-time local trajectory planning and control commands that satisfy the dual-mode flying car's land-air dynamic constraints based on behavioral decisions.

[0027] As a preferred option, the overall security control domain includes a security verification unit, a fault-tolerant control unit, an emergency decision-making unit, and a security redundancy unit.

[0028] The safety verification unit is used to perform full-dimensional safety verification on the control commands generated by the dual-modal decision planning domain. The full-dimensional safety verification includes collision risk verification, dynamic boundary verification, airspace and traffic rule compliance verification, and mode switching safety condition verification.

[0029] The fault-tolerant control unit employs a real-time diagnostic algorithm that combines deep learning and fault tree analysis to perform real-time diagnosis and classification of hardware and software faults across the entire system, encompassing perception, decision-making, execution, power, and communication. Fault-tolerant control strategies are then generated for different fault levels, including minor, moderate, severe, and fatal.

[0030] The emergency decision-making unit is used to generate graded emergency response strategies for control command verification failures, serious faults, fatal faults, or sudden emergency scenarios, thereby realizing a closed-loop emergency decision-making process from early warning to last resort.

[0031] The security redundancy unit is used to perform real-time monitoring, health assessment, and seamless primary / backup switching management of the perception fusion domain, dual-modal decision planning domain, global security control domain, execution control domain, air-ground collaborative communication domain, and redundant backup domain.

[0032] Preferably, the execution control domain includes a land execution unit, a flight execution unit, and an emergency execution unit. The land execution unit is used to perform steering, driving, and braking in land driving mode and takeoff and landing runway mode. The flight execution unit is used to perform attitude, thrust, and landing gear execution control in flight mode and transition mode. The emergency execution unit is used to perform actions in emergency scenarios. The emergency execution unit includes an aircraft parachute triggering device, an emergency power backup unit, an emergency landing buffer device, an in-cabin emergency alarm device, and an emergency positioning transmitter. The land execution unit, flight execution unit, and emergency execution unit all feed back their respective execution status to the overall safety control domain in real time. The land execution unit includes an electric power steering system, an electronic stability control system, an electric drive system, a hydraulic braking system, and an electronic parking brake system. The flight execution unit includes a flight control actuator, a rotor power controller, a ducted power controller, a control surface actuator, and a landing gear retraction actuator.

[0033] As a preferred option, the air-to-ground collaborative communication domain includes 5G or 6G vehicle-mounted terminals, low-altitude communication radios, ADS-B transceivers, V2X vehicle-to-infrastructure modules, and emergency satellite communication units.

[0034] Preferably, the redundant backup domain includes a redundant unit, an emergency unit, and a monitoring unit. The monitoring unit monitors the health status of the core functional domain and the redundant backup domain itself in real time. The redundant unit includes a dual-path decision controller, a dual-path fusion processor, a dual-path GNSS / INS integrated navigation system, a dual-path power supply system, a dual-path communication link system, and a redundant power system. The redundant backup domain adopts a three-level redundancy architecture of primary unit, backup unit, and emergency unit. The primary unit is the normal operating unit of the core functional domain, and the backup unit is the redundant unit in the redundant backup domain. The three-level redundancy architecture enables the following: when the monitoring unit detects a failure in the primary unit, it switches to the backup unit; when the monitoring unit detects a failure in both the primary unit and the backup unit, it switches to the emergency unit to take over the work of the corresponding domain. The software layer of the redundant backup domain adopts a heterogeneous operating system to avoid hardware and software common-mode failures.

[0035] The beneficial effects of this invention are as follows:

[0036] (1) This invention realizes the full-domain fusion autonomous driving of land and air dual modes, breaks the architectural defects of existing system splicing, and realizes seamless autonomous driving of land-air-land through unified perception fusion, decision planning and full-process safety control. There are no blind spots in the mode switching process, which greatly improves the continuity and stability of autonomous driving.

[0037] (2) Construct a vehicle-side full-domain safety management and control system, integrate safety management and control throughout the entire chain of perception, decision-making and execution, realize full-process protection of pre-command verification, real-time process monitoring, real-time fault diagnosis and emergency closed-loop handling, and fundamentally solve the core safety pain points of flying cars.

[0038] (3) Breaking through the limitations of the traditional "primary and backup two-level redundancy", we have innovatively designed a three-level redundancy architecture of "primary unit - backup unit - emergency unit" and paired it with an independent monitoring unit to realize full-process health status monitoring and rapid fault switching. The primary unit works normally, the backup unit is hot-backed up, and the emergency unit is an extreme backup, forming a "triple safety defense line". This solves the industry pain point of "single redundancy failure in cross-domain operation of dual-mode flying cars", ensuring that the core functions are uninterrupted. Even if both the primary and backup units fail, the emergency unit can still quickly take over the work, completely eliminating the risk of "single point failure leading to system loss of control". It directly meets the safety standards of manned aviation. The heterogeneous layout of software and hardware avoids common mode failure. The failure of a single component will not lead to system loss of control. The system reliability meets the safety requirements of manned aviation.

[0039] (4) Establish a full-scenario graded emergency response mechanism to achieve a closed-loop emergency response from fault tolerance correction to safety bottom line for different risk levels of faults and emergencies, maximize the protection of passenger life safety in extreme scenarios, and solve the core safety concerns of the commercialization of flying cars.

[0040] (5) The multi-source heterogeneous perception system is adapted to both land and air scenarios. The dual-chip fusion architecture of automotive and aviation grades ensures the accuracy of data spatiotemporal synchronization. The perception robustness in complex urban low-altitude environments is greatly improved, effectively reducing the rate of missed detection and false detection, and adapting to all-weather and all-scenario operation requirements. Attached Figure Description

[0041] Figure 1 This is a schematic diagram of the structure of the present invention;

[0042] Figure 2 This is a schematic diagram of the structure of the land-based sensing unit;

[0043] Figure 3 This is a schematic diagram of the flight sensing unit.

[0044] Figure 4 This is a schematic diagram of the structure of the global state perception unit;

[0045] Figure 5 This is a structural diagram of the emergency execution unit;

[0046] Figure 6 This is a schematic diagram of the land-based execution unit.

[0047] Figure 7 This is a structural diagram of the flight execution unit;

[0048] Figure 8 This is a schematic diagram of the structure of the air-to-ground collaborative communication domain;

[0049] Figure 9 This is a schematic diagram of the redundant backup domain structure. Detailed Implementation

[0050] The technical solution of the present invention will be further described below with reference to the accompanying drawings:

[0051] like Figure 1As shown, a dual-modal flying car vehicle-side all-domain safety autonomous driving system includes core functional domains, namely a perception fusion domain 100, a dual-modal decision planning domain 200, an all-domain safety management domain 300, an execution control domain 400, an air-to-ground collaborative communication domain 500, and a redundancy backup domain 600. The perception fusion domain 100 is used to collect multi-source heterogeneous perception data under various operating modes of the dual-modal flying car, and then fuse the multi-source heterogeneous perception data to output a unified and accurate all-domain environment model and vehicle full-state data, providing reliable data support for the decision planning of the dual-modal decision planning domain 200 and the safety management of the all-domain safety management domain 300. The multi-source heterogeneous perception data includes environmental state perception data, vehicle state perception data, flight state perception data, full system hardware state data, full system power state data, and full system safety state data. The bimodal decision-making and planning domain 200 is used to complete the full-process mode management, global path planning, behavior decision-making, and local trajectory planning for land driving mode, flight mode, and transition mode based on the global environment model and vehicle full-state data output by the perception fusion domain 100, and generate mode switching instructions and control instructions; the global safety management domain 300 is used to perform full-dimensional safety verification on the control instructions generated by the bimodal decision-making and planning domain 200, perform real-time diagnosis and classification of hardware and software faults in the entire system, execute fault-tolerant control and graded emergency response strategies, and perform real-time monitoring, health assessment, and seamless primary / backup switchover management of core functional domains; the execution control domain 400 is used to receive the instructions issued by the global safety management domain 300. The system implements compliant control commands to execute actions in land driving mode, takeoff and landing taxiing mode, flight mode, transition mode, and emergency scenarios, and feeds back the execution status to the full-domain safety control domain 300 in real time. The air-ground collaborative communication domain 500 is used to realize two-way communication between the vehicle and the ground control platform, airspace control system, other aircraft, and ground traffic facilities, synchronously reporting vehicle status, receiving control commands, and sharing traffic situation data. The redundant backup domain 600 serves as the core of safety redundancy assurance for the entire autonomous driving system. It is used to monitor the health status of the core functional domains and itself in real time. When an abnormal failure is detected in a core functional domain, the redundant backup domain 600 can quickly activate its internal redundant units or emergency units to take over the work of the corresponding domain.

[0052] like Figure 1As shown, the overall security control domain 300 interacts with the perception fusion domain 100, the dual-modal decision planning domain 200, the execution control domain 400, the air-to-ground collaborative communication domain 500, and the redundancy backup domain 600. Specifically, it sends self-test commands and fault diagnosis trigger signals to the perception fusion domain 100 and receives feedback from the perception fusion domain 100 on the health status of the perception system and sensor fault information for fault-tolerant control and graded handling. It also sends mode switching authorization or denial commands, emergency path correction commands, system readiness signals, or termination signals to the dual-modal decision planning domain 200 and receives synchronized path planning results, mode switching requests, and decision logic status from the dual-modal decision planning domain 200 for security verification. Compliance verification; sending emergency execution commands and primary / backup switchover commands to the execution control domain 400, and receiving feedback from the execution control domain 400 on the health status of execution units and actuator fault information to support fault diagnosis and emergency response; sending vehicle fault status, emergency alarm signals, and positioning data to the air-to-ground cooperative communication domain 500, and receiving feedback from the air-to-ground cooperative communication domain 500 on ground control commands, airspace status, and vehicle-road cooperative information to support emergency decision-making and route compliance verification; sending primary / backup switchover commands and redundant unit activation commands to the redundancy backup domain 600, and receiving feedback from the redundancy backup domain 600 on the health status of redundant systems and primary / backup link switchover status to support the monitoring and management of the full-domain safety control domain 300.

[0053] like Figure 2 As shown, the perception fusion domain 100 includes a land perception unit 101, a flight perception unit 102, a global state perception unit 103, and a multi-source heterogeneous fusion processing unit 104. The land perception unit 101 is used to collect environmental state perception data and vehicle state perception data during the land driving mode and take-off and landing taxiing phases. The land perception unit 101 includes a forward-looking binocular camera 1010, a four-way surround-view fisheye camera 1011, a forward-facing millimeter-wave radar 1012, an angular millimeter-wave radar 1013, an ultrasonic radar 1014, and a lidar 1015. The land driving mode refers to the working mode in which the dual-mode flying car relies on the ground driving mechanism to drive normally on ground conditions such as urban roads and ordinary roads. The take-off and landing taxiing phase refers to the take-off ground taxiing phase when the dual-mode flying car switches from land mode to flight mode, and the landing ground taxiing phase when switching from flight mode to land mode. In this invention, environmental state perception data refers to external environmental perception information such as the surrounding road traffic environment, obstacles, road surface conditions, traffic participants, signs and markings, and surrounding airspace obstacles of the vehicle during the land driving mode and take-off and landing taxiing phase; vehicle state perception data refers to the flying car's own operating condition parameters such as vehicle speed, driving attitude, position and heading, chassis condition, steering and braking, wheel speed, and vehicle attitude.

[0054] like Figure 3As shown, the flight sensing unit 102 is used to collect low-altitude environmental state perception data and flight state perception data in flight mode and transition mode. The flight sensing unit 102 includes a 360° solid-state lidar 1021, a long-range infrared camera 1022, a low-altitude meteorological sensor 1023, a barometric altimeter 1024, a GNSS and INS integrated navigation unit 1025, a differential BeiDou positioning module 1026, and an ADS-B airborne transponder 1027. Flight mode refers to the stable flight condition in which the flying car is completely detached from the ground and completes climb, cruise, route flight, and obstacle avoidance in the air.

[0055] Transition mode refers to the entire process of a flying car switching between land mode and flight mode, including intermediate transition conditions such as takeoff and hovering, ascent transition, approach and landing, and low-altitude slow descent.

[0056] Low-altitude environment status perception data mainly includes low-altitude obstacle distribution, surrounding aircraft position and status, low-altitude meteorological parameters, airspace environment status, and aerial obstacle contours and distance information, etc., representing low-altitude external environmental information. Flight status perception data mainly includes real-time flight position, altitude, flight attitude, heading and speed, spatial motion parameters, BeiDou differential positioning information, and airborne airspace interaction information, representing the flying car's own flight operation status parameters. The flight perception unit 102 is equipped with multiple types of dedicated aviation-grade perception and navigation equipment: 360° solid-state lidar and long-range infrared cameras enable all-weather low-altitude obstacle detection and 3D environment modeling; low-altitude meteorological sensors and barometric altimeters collect real-time low-altitude temperature, humidity, air pressure, wind speed and direction, and altitude information; GNSS and INS combined navigation units and differential BeiDou positioning modules enable high-precision continuous positioning and inertial navigation calculations, ensuring uninterrupted positioning in complex low-altitude environments; and an ADSB airborne transponder enables identity interaction and position sharing with airspace control and other aircraft, meeting the requirements for collaborative operation in low-altitude airspace.

[0057] like Figure 4 As shown, the global state perception unit 103 is used to collect hardware state data, power state data, and safety state data of the entire system. The global state perception unit 103 includes a land propulsion system state sensor 1031, a flight propulsion system state sensor 1032, a BMS battery management system 1033, a flight control state monitoring unit 1034, a braking state sensor 1035, a control surface state sensor 1036, a rotor actuator state sensor 1037, a door safety sensor 1038, a seat belt safety sensor 1039, and an emergency equipment cabin safety sensor 1040. The multi-source heterogeneous fusion processing unit 104 adopts a dual-chip heterogeneous architecture of automotive-grade and aerospace-grade, which is used to fuse and process multi-source heterogeneous perception data and output a unified and accurate global environment model and vehicle full state data.

[0058] The fusion processing specifically includes spatiotemporal synchronization of multi-source heterogeneous sensing data, target association matching, three-dimensional modeling of the entire environment, and real-time estimation of the vehicle's full state, in order to eliminate the time difference and spatial position deviation between multiple types of sensing data.

[0059] like Figure 1 As shown, the bimodal decision-making and planning domain 200 includes a mode management unit 201, a global path planning unit 202, a behavior decision-making unit 203, and a local trajectory planning unit 204.

[0060] The mode management unit 201 is used to identify the status of land mode, flight mode, and transition mode, define mode boundary conditions, determine switching trigger logic, authorize switching, and manage the entire switching process, and generate corresponding mode switching instructions. The mode management unit 201 is the core scheduling unit of the dual-modal decision planning domain 200, responsible for real-time status identification of the three operating conditions of land mode, flight mode, and transition mode; predefine the switching boundary constraints between each mode, and determine the switching trigger logic based on the vehicle's own status, environmental conditions, and airspace control conditions; at the same time, it authorizes the mode switching and performs closed-loop management of the entire switching sequence, process, and status transition, and finally outputs accurate and reliable mode switching instructions to ensure smooth and safe switching of multiple modes.

[0061] The global path planning unit 202 is used to integrate land traffic maps, low-altitude airspace maps, user destinations, airspace control requirements, and real-time traffic conditions to generate a land-air-land full-link global path plan. The global path planning unit 202 integrates basic geographic airspace data from land traffic maps and low-altitude airspace maps, combines user-defined destinations, real-time airspace control constraints, and real-time road and low-altitude traffic information, coordinates ground travel routes and low-altitude flight routes, and plans a complete land-air-land full-link global driving and flight path in one go, providing a top-level path basis for subsequent behavior decisions and trajectory planning.

[0062] The behavior decision-making unit 203 is used to generate behavior decisions that comply with traffic rules and airspace control requirements based on the global environment model and the land-air-land full-link global path planning. These behavior decisions include following other vehicles on land, changing lanes on land, braking on land, climbing, cruising, avoiding obstacles, takeoff in transition mode, hovering in transition mode, and landing in transition mode. Based on the global environment model and global path planning results output by perception fusion, the behavior decision-making unit 203 completes layered behavior decisions in accordance with ground traffic rules and low-altitude airspace control regulations. The behavior decisions cover typical behaviors across all operating conditions: ground conditions include following other vehicles on land, changing lanes on land, and braking on land; air conditions include climbing, cruising, and avoiding obstacles in flight; and mode transition conditions include takeoff in transition mode, hovering in transition mode, and landing in transition mode. Through reasonable behavior decisions, obstacles are avoided, control rules are followed, and flight follows the global path.

[0063] The local trajectory planning unit 204 is used to generate real-time local trajectory planning and control commands that satisfy the dual-mode flying car's land-air dynamic constraints based on behavioral decisions, including land steering / throttle / braking commands and flight attitude / thrust / control surface control commands.

[0064] like Figure 1 As shown, the overall security control domain 300 includes a security verification unit 301, a fault-tolerant control unit 302, an emergency decision-making unit 303, and a security redundancy unit 304.

[0065] The safety verification unit 301 is used to perform full-dimensional safety verification on the control commands generated by the dual-modal decision planning domain 200. The full-dimensional safety verification includes collision risk verification, dynamic boundary verification, airspace and traffic rule compliance verification, and mode switching safety condition verification.

[0066] The fault-tolerant control unit 302 employs a real-time diagnostic algorithm that combines deep learning and fault tree analysis to perform real-time diagnosis and classification of hardware and software faults across the entire system, encompassing perception, decision-making, execution, power, and communication. It then generates fault-tolerant control strategies for different fault levels, including minor, moderate, severe, and fatal.

[0067] The emergency decision-making unit 303 is used to generate a graded emergency response strategy for control command verification failure, serious fault, fatal fault, or sudden emergency scenario, thereby realizing a closed-loop emergency decision-making process from early warning to backup.

[0068] The security redundancy unit 304 is used to perform real-time monitoring, health assessment, and seamless primary / backup switching management of the perception fusion domain 100, dual-modal decision planning domain 200, full-domain security control domain 300, execution control domain 400, air-ground collaborative communication domain 500, and redundancy backup domain 600, covering the full-link redundancy of perception, decision-making, execution, power, communication, and power supply.

[0069] like Figures 5 to 7As shown, the execution control domain 400 includes a land execution unit 401, a flight execution unit 402, and an emergency execution unit 403. The land execution unit 401 is used to perform steering, driving, and braking in land driving mode and takeoff and landing run mode. The flight execution unit 402 is used to perform attitude, thrust, and landing gear execution control in flight mode and transition mode. The emergency execution unit 403 is used to perform actions in emergency scenarios. The emergency execution unit 403 includes a whole-aircraft parachute triggering device 4030, an emergency power backup unit 4031, an emergency landing buffer device 4032, an in-cabin emergency alarm device 4033, and an emergency positioning transmitter 4034. The whole-aircraft parachute triggering device 4030 is used to trigger the whole-aircraft parachute in a controlled manner when a major malfunction occurs in flight mode or transition mode and normal flight attitude cannot be maintained. It relies on the air resistance of the parachute to reduce the vehicle's descent speed, achieve a slow forced landing, avoid the risk of rapid high-altitude fall, and ensure the safety of passengers. The emergency power backup unit 4031 serves as a backup power source in case of failure of the main flight power and land propulsion. When the main propulsion system fails and shuts down or experiences power attenuation, it quickly takes over, providing short-term emergency thrust and lift to support the vehicle in hovering nearby, emergency return, or safe landing at a designated point. The emergency landing buffer device 4032, in emergency landing or landing in the wild without a proper landing site, absorbs the landing impact load through mechanical buffering and energy-absorbing structures, attenuating the impact force at the moment of landing and protecting the vehicle body structure, onboard equipment, and occupants from impact damage. The in-cabin emergency alarm device 4033, when the system detects a serious fault, a fatal fault, or enters the emergency response process, issues emergency alarm prompts to the occupants through sound, light, and voice, informing them of the current fault level and emergency response status, and reminding them to prepare for emergency evacuation. The emergency locator transmitter 404 automatically activates in emergency situations, continuously transmitting location distress signals and simultaneously reporting its own precise location and emergency status information, facilitating rapid location locating by ground control platforms and search and rescue forces for timely rescue. The land execution unit 401, flight execution unit 402, and emergency execution unit 403 all feed back their respective execution status to the global safety control domain 300 in real time. The land execution unit 401 includes an electric power steering system 4010, an electronic stability control system 4012, an electric drive system 4013, a hydraulic braking system 4014, and an electronic parking brake system 4015. The flight execution unit 402 includes a flight control actuator 4020, a rotor power controller 4021, a ducted power controller 4022, a control surface actuator 4023, and a landing gear retraction actuator 4024.

[0070] like Figure 8As shown, the air-to-ground cooperative communication domain 500 includes a 5G or 6G vehicle-mounted terminal 501, a low-altitude communication radio 502, an ADS-B transceiver 503, a V2X vehicle-to-infrastructure cooperative module 504, and an emergency satellite communication unit 505. The air-to-ground cooperative communication domain 500 is responsible for two-way communication between the vehicle and the ground control platform, airspace control system, other aircraft, and ground transportation facilities, reporting vehicle status in real time, receiving control instructions, and sharing traffic information.

[0071] like Figure 9 As shown, the redundant backup domain 600 internally includes a redundant unit 601, an emergency unit 602, and a monitoring unit 603. The monitoring unit 603 is used to monitor the health status of the core functional domain and the redundant backup domain 600 itself in real time. The redundant unit 601 includes a dual-path decision controller 6010, a dual-path fusion processor 6011, a dual-path GNSS / INS integrated navigation system 6012, a dual-path power supply system 6013, a dual-path communication link system 6014, and a redundant power system 6015. The redundant backup domain 600 adopts a three-level redundancy architecture of primary unit, backup unit, and emergency unit. The primary unit is the normal operating unit of the core functional domain, and the backup unit is the redundant unit in the redundant backup domain 600. The three-level redundancy architecture enables the following: when the monitoring unit 603 detects a failure in the primary unit, it switches to the backup unit; when the monitoring unit 603 detects a failure in both the primary unit and the backup unit, it switches to the emergency unit to take over the work of the corresponding domain. The software layer of the redundant backup domain 600 adopts a heterogeneous operating system to avoid hardware and software common-mode failures.

[0072] The working process of this invention is as follows:

[0073] (1) Phase 1: System power-on and full self-test

[0074] ①When the user powers on the system, the full-domain security control domain 300 prioritizes triggering the full system power-on self-test, covering the full-dimensional detection of hardware and software of the sensing, decision-making, execution, power, communication and redundancy units, and the full-domain status sensing unit 103 synchronously collects the initial state of the entire system;

[0075] ② If the self-test fails, the system will be prevented from starting and a pop-up window will indicate the location and cause of the fault; if the self-test passes, the system will enter the mode selection and task pre-planning stage.

[0076] (2) Phase Two: Mode Selection and Task Pre-planning and Pre-verification

[0077] ① The user inputs the destination and selects the autonomous driving mode (fully autonomous land and air dual mode / pure land driving / pure flight). The mode management unit 201 receives the instruction, and the global path planning unit 202 synchronously generates the initial global path.

[0078] ② The full-domain safety control domain 300 performs pre-verification on the initial path and mode selection, including takeoff / landing point compliance, airspace availability, land route legality, and system status matching; if the pre-verification fails, the user is prompted to change the destination or mode; if the pre-verification passes, the user enters the mode initialization and readiness stage.

[0079] (3) Phase 3: Mode initialization and autonomous driving readiness authorization

[0080] ①The mode management unit 201 completes the system initialization of the corresponding mode according to the selected initial mode, and at the same time completes the special checks before takeoff / before landing;

[0081] ② The 300-level full-domain security control domain completes the final safety readiness verification, confirming that all systems are normal and the environment meets the conditions for autonomous driving; if the verification passes, the autonomous driving authorization is released; if the verification fails, it returns to the initialization stage and prompts the reason for the fault.

[0082] (4) Phase 4: Dual-modal automated driving execution and real-time safety closed-loop management

[0083] ① The multi-source heterogeneous fusion processing unit 104 collects environmental and status data in real time. The fusion processor completes spatiotemporal synchronization and fusion, and outputs a unified global environmental model and vehicle full status data, which are synchronized to the dual-modal decision planning domain 200 and the global safety control domain 300.

[0084] ② The dual-modal decision planning domain 200, based on fused data and global path, completes behavioral decisions and local trajectory planning, generates control commands, and simultaneously sends the commands to the global security management domain 300;

[0085] ③ The full-domain security control domain performs real-time security verification on control commands and simultaneously completes real-time fault diagnosis for the entire system, divided into two branches:

[0086] a. Normal branch: After the security check is passed and there is no fault or only a minor fault, the instruction is sent to the execution control domain 400 after fault tolerance correction. The execution unit completes the corresponding action, and the execution status is fed back to the full domain security control domain 300 in real time, forming a closed loop and continuously executing in a loop.

[0087] b. Abnormal branch: If the security check fails or a general or above fault occurs, the control command will be immediately intercepted, triggering the emergency decision unit 303 and entering the emergency response phase.

[0088] ④ If a user triggers a mode switching request during operation, the mode management unit 201 first sends the request to the global security control domain 300 to complete the full-dimensional verification of the mode switching security conditions; if the verification passes, a smooth mode switching is performed, and the entire process is monitored by the global security control domain 300; if the verification fails, the switching request is rejected, the current mode is maintained, and the reason is displayed.

[0089] (5) Tiered emergency response closed loop

[0090] ① Emergency Decision Unit 303 executes a three-level emergency response strategy based on the fault level and the risk level of the emergency scenario, achieving full-scenario safety assurance:

[0091] a. Level 1 Emergency (Minor Fault / Low Risk): Triggers fault-tolerant control, corrects control commands in real time, issues and executes them, records fault information, continuously monitors system status, and returns to the normal execution loop;

[0092] b. Level 2 Emergency (General Fault / Medium Risk): Immediately generate an emergency path to the nearest safe landing / parking point. After safety verification, control the vehicle to terminate the mission at the nearest safe landing / parking point. After landing / parking, power off and lock the system, and display fault details.

[0093] c. Level 3 Emergency (Critical Failure / High Risk, such as in-flight power failure, extreme collision risk): Immediately trigger the entire emergency response process, including emergency landing trajectory planning, emergency power unit activation, whole-aircraft parachute activation, landing buffer device activation, emergency alarm and location full reporting, and closed-loop execution throughout until the vehicle comes to a safe stop, maximizing the safety of the occupants;

[0094] (6) Phase Six: Task Completion and System Power-Off

[0095] Once the vehicle arrives at its destination and switches to a stationary land-based state, the entire system status is checked after the 300-level safety control domain completes its task. After confirming that there are no abnormalities and with user confirmation, the system is powered down, and the entire process ends.

[0096] The complete embodiment of the entire process of this invention is as follows:

[0097] (1) System startup and self-test: After the user gets on the vehicle and powers on the system, the full-domain safety control domain 300 immediately triggers a full-system self-test, including full-dimensional detection of land perception, flight perception, power system, flight control system, parachute emergency device, etc. At the same time, the BMS battery management system 1033 and the full-domain status perception unit 103 complete the collection of battery and hardware status; the self-test is completed within 3 seconds, all systems are normal, and the system enters the ready state;

[0098] (2) Task planning and pre-verification: When the user enters the destination on the vehicle and selects "fully autonomous land and air dual-mode automatic driving", the system automatically matches the low-altitude routes from the starting point to the nearest vertical take-off and landing field, from the take-off and landing field to the destination take-off and landing field, and the land route from the destination take-off and landing field to the destination park, generating a global path; the full-domain safety control domain 300 simultaneously completes the airspace application verification, take-off and landing field availability verification, and path compliance verification. If the pre-verification is passed, the mode initialization permission is released;

[0099] (3) Land mode autonomous driving to take-off and landing site: The mode management unit 201 initializes the land autonomous driving mode. After the full domain safety control domain 300 completes the readiness verification, it releases the autonomous driving authorization. After the vehicle starts, the land perception unit 101 collects the road environment in real time, the fusion processor completes the environment modeling, and the dual-modal decision planning domain 200 generates behavioral decisions such as following, changing lanes, and turning. All control commands are verified by the safety verification unit 301 and then sent to the land execution unit 401 to execute the control actions. The entire process is monitored in real time by the full domain safety control domain 300. There are no abnormalities, and the vehicle arrives at the take-off and landing site smoothly.

[0100] (4) Mode switching and takeoff phase: After the vehicle arrives at the designated takeoff point of the takeoff and landing field, the user confirms the takeoff, and the mode management unit 201 sends a "land to flight" mode switching request to the full-domain safety control domain 300; the full-domain safety control domain 300 completes the special pre-takeoff inspection, including full-dimensional verification of the flight control system, power system, meteorological environment, airspace authorization, emergency devices, etc. If the verification is passed, the mode switching is authorized; the mode management unit 201 completes the land system lock-up and flight system activation, the dual-modal decision planning domain 200 generates the takeoff trajectory, and the control command is sent to the flight execution unit 402 after safety verification, to complete vertical takeoff / runway takeoff, climb, and enter the predetermined cruise route.

[0101] (5) Flight cruise autopilot phase: During the cruise, the flight perception unit 102 collects low-altitude obstacles, surrounding aircraft and meteorological environment data in real time, GNSS / INS integrated navigation provides real-time positioning, and the fusion processor completes the modeling of the low-altitude environment in the whole domain; the dual-modal decision planning domain 200 optimizes the cruise trajectory in real time, avoids air obstacles and other aircraft, and all instructions are executed after safety verification.

[0102] (6) Handling of abnormalities during flight cruise:

[0103] ① When the system detects a minor fault in rotor speed sensor No. 1, the fault-tolerant control unit 302 immediately completes the fault classification, triggers fault-tolerant control, and the safety redundancy management unit 304 seamlessly switches to the redundant backup sensor. The system cruises normally and records the fault information to complete the first-level emergency response.

[0104] ② During the cruise, if a small drone suddenly enters from the front, the flight perception unit 102 identifies it 300 meters in advance, the fusion processor completes the target trajectory prediction, the safety verification unit 301 determines that there is a collision risk on the original route, immediately intercepts the original control command, the emergency decision unit 303 generates an avoidance trajectory, and after safety verification, it is issued and executed to complete the smooth avoidance, avoid the collision risk, and then return to the predetermined route.

[0105] (7) Landing and mode switching: When the vehicle approaches the destination take-off and landing field, the dual-modal decision planning domain 200 generates the landing trajectory. The mode management unit 201 sends a flight to land mode switching request to the global safety control domain 300. After the safety verification is passed, landing is authorized. The flight execution unit 402 completes descent, hovering and precise landing. The mode management unit 201 completes flight system locking and land system activation, and switches to land autopilot mode.

[0106] (8) End point autonomous driving and mission completion: The vehicle departs from the take-off and landing site and drives autonomously to the designated parking spot in the destination park. After parking smoothly, the full-domain safety control domain 300 completes the full system status check. After confirming that there are no abnormalities, the system is powered down after user confirmation, and the full-process autonomous driving mission is completed.

[0107] The core advantage of this invention lies in constructing a fully integrated dual-modal autonomous driving safety system encompassing "perception-decision-control-execution-coordination-redundancy." Through deep collaboration and precise division of labor across six core functional domains, it achieves seamless automatic switching and full-condition safety coverage across land, flight, and transition modes. It innovatively adopts a three-level redundancy architecture of main unit, backup unit, and emergency unit, coupled with dual-path key component redundancy design and heterogeneous hardware and software layout, fundamentally avoiding common-mode failures and ensuring that the failure of a single component or link does not affect the core functions of the system, meeting manned aviation-grade safety requirements. Relying on dedicated land-air multi-source sensing equipment and dual-chip heterogeneous fusion processing technology, it accurately collects and fuses data. Comprehensive environmental, vehicle, flight, and system status data provide reliable support for decision-making and planning. Through comprehensive command verification, four-level fault diagnosis, and tiered emergency response strategies within the all-domain safety control domain, a closed-loop safety control system is achieved, encompassing everything from minor fault tolerance correction to critical fault protection. Utilizing a multi-link communication design within the air-to-ground collaborative communication domain, real-time interaction between the vehicle and ground control, airspace management, and other traffic participants is ensured, guaranteeing cross-domain compliance and collaboration. This effectively addresses the pain points of existing dual-modal flying car systems, such as fragmentation, insufficient safety redundancy, and poor adaptability to complex operating conditions, significantly improving the reliability, safety, and commercialization potential of autonomous driving systems. Compared to existing technologies, this patent employs a dual-modal flying car fusion strategy, designing the entire process from perception, planning, control, and redundancy diagnosis in both flight and ground phases. This overcomes the fragmented nature of existing distributed system architectures and control systems, fundamentally enhancing the integrated capabilities of flying cars and facilitating their future commercialization and cost reduction.

[0108] It should be noted that the above examples are merely one specific embodiment of the present invention. Obviously, the present invention is not limited to the above embodiments and many variations are possible. In short, all variations that can be directly derived or conceived by those skilled in the art from the content disclosed in this invention should be considered within the scope of protection of this invention.

Claims

1. A dual-modal flying car vehicle-side all-domain safety autonomous driving system, comprising core functional domains, the core functional domains including a perception fusion domain (100), a dual-modal decision planning domain (200), an all-domain safety control domain (300), an execution control domain (400), an air-ground collaborative communication domain (500), and a redundancy backup domain (600). The perception fusion domain (100) is used to collect multi-source heterogeneous perception data under various operating modes of the dual-modal flying car, and then to fuse the multi-source heterogeneous perception data to output a unified and accurate global environment model and vehicle full-state data, providing reliable data support for decision planning in the dual-modal decision planning domain (200) and safety management in the global safety management domain (300). The dual-modal decision planning domain (200) is used to complete the full-process mode management, global path planning, behavior decision-making and local trajectory planning of land mode, flight mode and transition mode based on the full-domain environment model and vehicle full-state data output by the perception fusion domain (100), and generate mode switching instructions and control instructions. The full-domain security control domain (300) is used to perform full-dimensional security verification on the control commands generated by the dual-modal decision planning domain (200), perform real-time diagnosis and classification of hardware and software faults in the entire system, execute fault-tolerant control and graded emergency response strategies, and perform real-time monitoring, health assessment and seamless switching management of the core functional domain. The execution control domain (400) is used to receive compliance control instructions issued by the global security control domain (300), complete the execution of actions in land mode, take-off and landing taxiing mode, flight mode, transition mode and emergency scenario, and feed back the execution status to the global security control domain (300) in real time. The air-ground collaborative communication domain (500) is used to realize two-way communication between the vehicle and the ground control platform, airspace control system, other aircraft and ground transportation facilities, and to simultaneously report vehicle status, receive control instructions and share traffic situation data. The redundant backup domain (600) serves as the core of safety redundancy for the entire autonomous driving system. It is used to monitor the health status of the core functional domain and itself in real time. When an abnormal fault is detected in the core functional domain, the redundant backup domain (600) can quickly activate its internal redundant unit or emergency unit to take over the work of the corresponding domain.

2. The dual-mode flying car vehicle-side all-domain safety automated driving system according to claim 1, characterized in that, The multi-source heterogeneous sensing data includes environmental state sensing data, vehicle state sensing data, flight state sensing data, full system hardware state data, full system power state data, and full system safety state data.

3. The dual-mode flying car end-to-end safety automatic driving system according to claim 2, characterized in that, The global security control domain (300) interacts with the perception fusion domain (100), the dual-modal decision planning domain (200), the execution control domain (400), the air-ground collaborative communication domain (500), and the redundancy backup domain (600). Specifically, it sends self-test instructions and fault diagnosis trigger signals to the perception fusion domain (100) and receives feedback from the perception fusion domain (100) on the health status of the perception system and sensor fault information for fault-tolerant control and graded handling. It sends mode switching authorization or rejection instructions or emergency path correction instructions or system ready signals or termination signals to the dual-modal decision planning domain (200) and receives path planning results, mode switching requests, and decision logic status synchronized by the dual-modal decision planning domain (200) for security verification and compliance verification. Send emergency execution commands and primary / backup switching commands to the execution control domain (400), and receive the execution unit health status and actuator fault information fed back by the execution control domain (400) to support fault diagnosis and emergency response; send vehicle fault status, emergency alarm signals, and positioning data to the air-ground cooperative communication domain (500), and receive the ground control commands, airspace status, and vehicle-road cooperative information fed back by the air-ground cooperative communication domain (500) to support emergency decision-making and path compliance verification; send primary / backup switching commands and redundant unit activation commands to the redundant backup domain (600), and receive the redundant system health status and primary / backup link switching status fed back by the redundant backup domain (600) to support the monitoring and management of the full-domain safety control domain (300).

4. The dual-mode flying car vehicle-side all-domain safety automated driving system according to claim 2, characterized in that, The perception fusion domain (100) includes a land perception unit (101), a flight perception unit (102), a global state perception unit (103), and a multi-source heterogeneous fusion processing unit (104). The land perception unit (101) is used to collect environmental state perception data and vehicle state perception data during land travel mode and takeoff and landing rollout phases. The land perception unit (101) includes a forward-looking binocular camera (1010), a four-way surround-view fisheye camera (1011), a forward-looking millimeter-wave radar (1012), an angular millimeter-wave radar (1013), an ultrasonic radar (1014), and a lidar (1015). The flight perception unit (102) is used to collect low-altitude environmental state perception data and flight state perception data during flight mode and transition mode. The flight perception unit (102) includes a 360° solid-state lidar (1021), a long-range infrared camera (1022), a low-altitude meteorological sensor (1023), a barometric altimeter (1024), and a GNSS and INS integrated navigation unit. The system includes a multi-source heterogeneous fusion processing unit (1025), a differential Beidou positioning module (1026), and an ADS-B airborne transponder (1027). The global state perception unit (103) is used to collect hardware state data, power state data, and safety state data of the entire system. The global state perception unit (103) includes a land propulsion system state sensor (1031), a flight propulsion system state sensor (1032), a BMS battery management system (1033), a flight control state monitoring unit (1034), a braking state sensor (1035), a control surface state sensor (1036), a rotor actuator state sensor (1037), a door safety sensor (1038), a seat belt safety sensor (1039), and an emergency equipment cabin safety sensor (1040). The multi-source heterogeneous fusion processing unit (104) adopts a dual-chip heterogeneous architecture of automotive-grade and aerospace-grade, which is used to fuse and process multi-source heterogeneous perception data and output a unified and accurate global environment model and vehicle full state data.

5. The dual-mode flying car end-to-end safety automated driving system according to claim 4, characterized in that, The fusion process specifically includes spatiotemporal synchronization of multi-source heterogeneous sensing data, target association matching, three-dimensional modeling of the entire environment, and real-time estimation of the vehicle's full state, in order to eliminate the time difference and spatial position deviation between multiple types of sensing data.

6. The dual-mode flying car vehicle-side all-domain safety automated driving system according to claim 2, characterized in that, The bimodal decision planning domain (200) includes a mode management unit (201), a global path planning unit (202), a behavior decision unit (203), and a local trajectory planning unit (204). The mode management unit (201) is used to identify the status of land mode, define mode boundary conditions, judge switching trigger logic, authorize switching and control the entire switching process of land mode, flight mode and transition mode, and generate corresponding mode switching instructions. The global path planning unit (202) is used to integrate land traffic map, low-altitude airspace map, user destination, airspace control requirements, and real-time traffic situation to generate a land-air-land full-link global path plan. The behavioral decision unit (203) is used to generate behavioral decisions that comply with traffic rules and airspace control requirements based on the global environment model and the land-air-land full-link global path planning. The behavioral decisions include land following, land lane changing, land braking, flight climb, flight cruise, flight avoidance, transition mode takeoff, transition mode hovering, and transition mode landing. The local trajectory planning unit (204) is used to generate real-time local trajectory planning and control commands that satisfy the dual dynamic constraints of the dual-modal flying car on land and in the air based on behavioral decisions.

7. The dual-mode flying car end-to-end safety automated driving system according to claim 6, characterized in that, The global security control domain (300) includes a security verification unit (301), a fault-tolerant control unit (302), an emergency decision-making unit (303), and a security redundancy unit (304). The safety verification unit (301) is used to perform full-dimensional safety verification on the control commands generated by the bimodal decision planning domain (200). The full-dimensional safety verification includes collision risk verification, dynamic boundary verification, airspace and traffic rule compliance verification, and mode switching safety condition verification. The fault-tolerant control unit (302) employs a real-time diagnostic algorithm that combines deep learning and fault tree analysis to perform real-time diagnosis and classification of hardware and software faults across the entire system, encompassing perception, decision-making, execution, power, and communication. It then generates fault-tolerant control strategies for different fault levels, including minor, moderate, severe, and fatal. The emergency decision-making unit (303) is used to generate a graded emergency response strategy for control command verification failure, serious fault, fatal fault or sudden emergency scenario, so as to realize a closed-loop emergency decision-making from early warning to last resort. The security redundancy unit (304) is used to perform real-time monitoring, health assessment and seamless primary / backup switching management of the perception fusion domain (100), the bimodal decision planning domain (200), the global security control domain (300), the execution control domain (400), the air-ground collaborative communication domain (500), and the redundancy backup domain (600).

8. The dual-mode flying car end-to-end safety automatic driving system according to claim 2, characterized in that, The execution control domain (400) includes a land execution unit (401), a flight execution unit (402), and an emergency execution unit (403). The land execution unit (401) is used to perform steering, driving, and braking in land driving mode and takeoff and landing runway mode. The flight execution unit (402) is used to perform attitude, thrust, and landing gear execution control in flight mode and transition mode. The emergency execution unit (403) is used to perform actions in emergency scenarios. The emergency execution unit (403) includes a whole-aircraft parachute triggering device (4030), an emergency power backup unit (4031), an emergency landing buffer device (4032), an in-cabin emergency alarm device (4033), and an emergency positioning device. The transmitter (4034), the land execution unit (401), the flight execution unit (402) and the emergency execution unit (403) all feed back their respective execution status to the global safety control domain (300) in real time. The land execution unit (401) includes an electric power steering system (4010), an electronic stability control system (4011), an electric drive system (4012), a hydraulic braking system (4013) and an electronic parking brake system (4014). The flight execution unit (402) includes a flight control actuator (4020), a rotor power controller (4021), a ducted power controller (4022), a control surface actuator (4023), and a landing gear retraction actuator (4024).

9. The dual-mode flying car end-to-end safety automatic driving system according to claim 2, characterized in that, The air-to-ground cooperative communication domain (500) includes a 5G or 6G vehicle-mounted terminal (501), a low-altitude communication radio (502), an ADS-B transceiver (503), a V2X vehicle-to-everything cooperative module (504), and an emergency satellite communication unit (505).

10. The dual-mode flying car end-to-end safety automatic driving system according to claim 2, characterized in that, The redundant backup domain (600) is equipped with a redundancy unit (601), an emergency unit (602), and a monitoring unit (603). The monitoring unit (603) is used to monitor the health status of the core functional domain and the redundant backup domain (600) in real time. The redundancy unit (601) includes a dual-path decision controller (6010), a dual-path fusion processor (6011), a dual-path GNSS / INS integrated navigation system (6012), a dual-path power supply system (6013), a dual-path communication link system (6014), and a redundant power system (6015). The redundant backup domain (600) adopts a three-level redundancy architecture of primary unit, backup unit and emergency unit. The primary unit is the normal working unit of the core functional domain, and the backup unit is the redundant unit in the redundant backup domain (600). The three-level redundancy architecture realizes that when the monitoring unit (603) detects a failure of the primary unit, it switches to the backup unit. When the monitoring unit (603) detects a failure of both the primary unit and the backup unit, it switches to the emergency unit to take over the work of the corresponding domain. The software layer of the redundant backup domain (600) adopts a heterogeneous operating system to avoid hardware and software common mode failures.