ROV safety control system, method, electronic device, storage medium

CN122795084APending Publication Date: 2026-09-22DEEP SEA HOMO SAPIENS (GUANGZHOU) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610905908.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-23
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

但是二元故障判定难以适应推进器效率衰减、叶片缠绕、堵转前兆、电调温升、电流异常、转速偏差、外部海流扰动相互混淆的情况

Benefits of technology

(1)通过将候选控制量经过安全壳模块,防止异常输出直接驱动ROV的推进器,提升在高风险水下场景中的安全性;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122795084A_ABST
    Figure CN122795084A_ABST
Patent Text Reader

Abstract

The application discloses a ROV safety control system, method, electronic equipment and storage medium. The system comprises a fusion estimation module, a control generation module, a safety shell module and a propeller action generation module. The fusion estimation module processes the multi-sensor observation data and communication quality data of the ROV by using a fusion algorithm to obtain fusion data. The control generation module performs control optimization processing on the basis of the fusion data, device health data of the ROV and task boundary constraints performed by the ROV to generate a candidate control amount. The safety shell module performs safety constraint filtering processing on the candidate control amount to obtain a safety control amount. The propeller action generation module performs propeller power distribution processing on the basis of the safety control amount and the device health data to obtain a propeller action instruction of the ROV. The application is used for realizing action safety control on the ROV.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of robot equipment, specifically relating to an ROV safety control system, method, electronic device, and storage medium. Background Technology

[0002] Currently, remotely operated underwater vehicles (ROVs) typically have six or eight thrusters to meet the requirement of at least six degrees of freedom control, and they often carry an underwater vehicle manipulator system (UVMS). ROVs perform motion control, safety constraint control, thruster fault-tolerant allocation, and operational evidence recording in complex underwater environments. Application scenarios include near-structure inspection, confined space inspection, remote operation in hazardous environments, long-cable operations, and maintenance of high-value marine engineering facilities, necessitating safe control of the power of each thruster.

[0003] In existing technologies, ROV motion control typically employs remote control commands combined with underlying PID control, attitude maintenance, depth and heading control, and simple path tracking. Some systems incorporate inertial navigation systems (INS), Doppler logs (DVL), depth gauges, ultra-short baseline underwater acoustic positioning (USBL), vision systems, and forward-looking sonar for positioning and navigation. Others utilize model predictive control (MPC), adaptive control, robust control, and disturbance observers for disturbance rejection. Currently, ROV navigation fusion, controller selection, thruster fault handling, communication delay handling, and safety monitoring functions are independent. Safety logic is often limited to fixed threshold alarms, emergency shutdown, and operator takeover. While existing technologies such as learning-enhanced control, deep reinforcement learning, data-driven predictive control, and PINN residual compensation based on physical information neural networks can improve trajectory tracking performance under complex hydrodynamic and ocean current disturbances, they often face challenges in actual ROV deployments, including insufficient interpretability, inadequate training data coverage, sensitivity to sensor anomalies, and authentication difficulties. If the learner directly outputs thruster commands or takes over closed-loop control, collisions, cable entanglement, mud disturbance, attitude instability, or mission failure may occur due to a single abnormal inference when near the seabed, pipelines, platform jackets, aquaculture cages, nuclear facility pools, or other high-risk structures. Therefore, safety protection schemes and thruster fault-tolerant control are required. Existing safety protection schemes mainly rely on static safety boundaries, such as limiting maximum speed, maximum depth, thruster saturation, attitude angle, or battery thresholds. However, static safety boundary schemes are prone to abrupt control switching, increased operator burden, or inconsistent backoff actions when communication links deteriorate or sensor confidence decreases. In existing ROV technologies, thruster fault-tolerant control often employs a binary fault determination mechanism, whereby a thruster is determined to be faulty and the thrust distribution matrix is ​​switched or the thruster is shut down directly. However, binary fault determination is ill-suited to situations where thruster efficiency degradation, blade entanglement, stall precursors, ESC temperature rise, abnormal current, speed deviation, and external ocean current disturbances are all intertwined. Furthermore, existing ROV operation logs are primarily used for post-event maintenance or as standard black box recordings, typically only recording operating commands, sensor data, and some control outputs. They lack information related to various intermediate processing steps and lack a replayable, traceable, and shadow-mode-verification-compatible evidence chain, making it difficult to support safe iteration of learning controllers, fault reproduction, third-party audits, and compliance certifications.

[0004] In summary, existing ROV technologies suffer from several problems: the control performance is disconnected from operational safety constraints, making it difficult to safely implement learning or optimization control; safety monitoring cannot be tailored in real time, making it difficult to ensure that the final control commands meet the static safety boundaries of underwater operations in each execution cycle; thruster failure handling is too rigid, making it difficult to achieve soft switching and mission continuity; communication quality, sensor confidence, and fault health status are not uniformly managed at the autonomous level; and there is a lack of log evidence chains that can reproduce the control process, shadow mode, retraining, and compliance certification. Summary of the Invention

[0005] To address one or more of the aforementioned problems, this application provides a first aspect of an ROV safety control system, a second aspect of an ROV safety control method, a third aspect of an electronic device for implementing the second aspect, and a fourth aspect of a storage medium for implementing the second aspect. This application provides a technical solution for controlling or adjusting non-electrical variables of remotely operated underwater vehicles (ROVs), thereby enabling safe control of power distribution and movement of multiple thrusters within the ROV.

[0006] The technical solution of this application is as follows.

[0007] In a first aspect, the ROV safety control system of this application includes: The fusion estimation module is used to process the multi-sensor observation data and communication quality data of the ROV using a fusion algorithm to obtain fused data; The control generation module is used to generate candidate control quantities by performing control optimization processing based on the fused data, ROV equipment health data, and the task boundary constraints performed by the ROV. The safe containment module is used to perform safety constraint filtering on candidate control variables to obtain safe control variables; The thruster action generation module is used to obtain the ROV's thruster action commands by processing the propulsion power distribution based on safety control variables and equipment health data.

[0008] As one implementation of the first aspect, it also includes a sensing module; The perception module is used to acquire multi-sensor observation data, communication quality data, equipment health data, and task boundary constraints.

[0009] As one implementation of the first aspect, a log evidence module is also included; The log evidence module is used to record data in a structured manner.

[0010] As one implementation of the first aspect, before processing using the fusion algorithm, it further includes: Based on multi-sensor observation data and communication quality data, time alignment, coordinate unification, and confidence gating are performed on the multi-sensor observation data.

[0011] As one implementation of the first aspect, the control optimization process includes: The ROV's comprehensive operational risk score is calculated based on one or more of the following: fused data, equipment health data, and task boundary constraints. Then, the ROV's autonomy level is determined. Basic control quantities are generated based on a minimum control algorithm; Optimized control quantities are generated based on optimized control algorithms; Compensation amounts are generated based on learning-enhanced algorithms; Based on the ROV's comprehensive operational risk score and ROV autonomy level, data arbitration is conducted on one or more of the basic control variables, optimized control variables, and compensation variables to form candidate control variables.

[0012] As one implementation of the first aspect, the security constraint filtering process includes: Candidate control variables that satisfy safety constraints are directly used as safety control variables; For candidate control variables that do not meet the safety constraints, perform the closest safety control solution to generate a safety control variable that meets the safety constraints and has the smallest deviation from the candidate control variable.

[0013] As one implementation of the first aspect, propulsion power distribution includes: Generate a thruster action matrix corresponding to multiple thrusters based on the safety control parameters; Based on the equipment health data, the output distribution control of the thruster action matrix is ​​processed to generate thruster action commands that adjust the power output of each of the multiple thrusters.

[0014] Secondly, an ROV safety control method of this application, implemented based on the ROV safety control system of the first aspect, includes: The multi-sensor observation data and communication quality data of ROV are processed using a fusion algorithm to obtain fused data; Based on the fused data, ROV equipment health data, and the task boundary constraints performed by the ROV, control optimization processing is performed to generate candidate control variables; The candidate control variables are filtered by safety constraints to obtain the safe control variables; The propulsion power distribution is processed based on safety control parameters and equipment health data to obtain the ROV's thruster action commands.

[0015] Thirdly, an electronic device according to this application includes a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement the ROV safety control method of the second aspect.

[0016] Fourthly, one storage medium of this application is a computer-readable storage medium storing computer instructions for causing a computer to implement the ROV safety control method of the second aspect.

[0017] Compared with the prior art, the advantages of this application are as follows: (1) By passing the candidate control quantity through the containment module, abnormal outputs are prevented from directly driving the ROV's thrusters, thus improving safety in high-risk underwater scenarios. (2) Integrating health status and communication quality for switching control modes, it no longer relies on a single threshold alarm and can control the ROV according to the actual operational risks and select reasonable control quantities. (3) Using ROV health for thrust distribution can reduce control abrupt changes and improve the ability to continue the mission when the thruster is degraded, entangled, stalled, or has abnormal temperature rise compared to the approach of binary faults. (4) Structured recording of various data and information during the control process facilitates fault reproduction, regulatory review, etc.; (5) It is compatible with different autonomous levels such as direct manual control, shared control, and supervised autonomous control, and meets the needs of inspection-level ROV, operation-level ROV, ROV with robotic arm, stationary ROV, underwater glider and other types. Attached Figure Description

[0018] Figure 1 This is a schematic diagram of the structural framework of an ROV safety control system according to this application.

[0019] Figure 2 This is a flowchart illustrating a ROV safety control method according to this application.

[0020] Figure 3 This is a structural framework diagram of an electronic device according to this application. Detailed Implementation

[0021] Referring to the illustrations, the principles of this application are illustrated by way of example implementation in a suitable operating environment. The following description is based on the specific embodiments of this application as illustrated, and should not be construed as limiting other specific embodiments not detailed herein.

[0022] In this application, the ROV object for safety control can be configured with various types of sensors, such as four-thruster, six-thruster, eight-thruster, vector thruster, reconfigurable thruster, or rudder surface thruster combination. The remote control station and the ROV body can communicate via copper cable, fiber optic cable, blue-green light communication, relay buoy, or USV relay. ROV autonomy levels can be categorized into L0 (direct human control), L1 (safety assistance), L2 (supervised autonomy), L3 (conservative hovering or return to base), and L4 (emergency response). Under L0 direct human control, remote control inputs still require safety constraint filtering. Under L1 safety assistance, remote control inputs are subject to amplitude limiting, speed constraints, and collision risk trimming. Under L2 supervised autonomy, optimized control algorithms and learning-enhanced algorithms can participate in trajectory tracking and inspection coverage, but all commands still require safety constraint filtering. Under L3 conservative hovering or return to base, the ROV ceases unnecessary tasks and performs hovering, depth control, cable retraction, low-speed obstacle avoidance, and return to the safety corridor. Under L4 emergency response, the ROV performs emergency thrust stop, load release, ascent, alarm activation, and awaits human rescue. The specific actions corresponding to each ROV autonomy level can be configured according to the ROV's structure and operational specifications. ROV autonomy levels range from L0 to L4, representing the degree of human intervention from highest to lowest.

[0023] like Figure 1 As shown, this application provides an ROV safety control system, which can be set in one or more of the ROV's mother ship control station, shore control station, and underwater control panel, including a sensing module, a fusion estimation module, a control generation module, a containment module, a thruster action generation module, and a log evidence module.

[0024] In this embodiment, optionally, the perception module, fusion estimation module, control generation module, containment module, and thruster motion generation module are connected to the log evidence module; the perception module, fusion estimation module, control generation module, containment module, and thruster motion generation module are connected sequentially. The thruster motion generation module is communicatively connected to the ROV's thrusters.

[0025] The perception module is used to acquire multi-sensor observation data, communication quality data, equipment health data, and task boundary constraints.

[0026] Optionally in this embodiment, the sensing module is connected to the storage of observation data processing results from various sensors in the ROV, and obtains the corresponding multi-sensor observation data from the sensor observation data processing results storage. The sensors used in the ROV include, but are not limited to, inertial navigation systems, Doppler logs, forward-looking sonar, visual cameras, structured light cameras, lidar, underwater acoustic locators, multibeam sonar, depth gauges, altimeters, and magnetic compasses. The combination of sensor types used in different embodiments of the ROV is adjusted based on actual mission requirements.

[0027] In this embodiment, the multi-sensor observation data includes, but is not limited to, the ROV's position, velocity, attitude, angular velocity, depth, height above the bottom, distance from obstacles, and other information representing the ROV's motion state and underwater environment, which can be used as a basis for subsequent navigation and safety boundary calculations.

[0028] In this embodiment, the sensing module can also be used to add timestamps, coordinate system identifiers, sensor health identifiers, observation quality scores, and other identifiers related to the characteristics of the data to the multi-sensor observation data.

[0029] In this embodiment, equipment health data describes the operational status of various devices in the ROV, such as thrusters, power dispatchers, power supplies, sealed cabins, robotic arms, and cables. This includes, but is not limited to, thruster current, bus voltage, rotational speed, temperature rise, vibration, water leakage status, battery SOC, cable tension, cabin humidity, thruster commands, rotational speed residuals, thruster commands, current residuals, continuous health status, and failure probability. Equipment health data is obtained by collecting data from the corresponding input / output and sensor data of the relevant devices in the ROV, calculating the data according to their specific health definitions, and storing it in the corresponding equipment health data processing result memory. In this embodiment, the sensing module retrieves the corresponding equipment health data by accessing the corresponding equipment health data processing result memory.

[0030] In this embodiment, communication quality data describes whether the information quality of the ROV's communication link is good during one-way and / or two-way transmission. This includes, but is not limited to, latency, jitter, packet loss rate, effective bandwidth, video encoding usage, telemetry priority, control command confirmation status, remote operator input quality, and communication link quality. The communication quality data is calculated based on the corresponding data collected by the relevant devices in the ROV according to their respective definitions and stored in the corresponding communication quality data processing result memory. In this embodiment, the sensing module obtains the corresponding communication quality data by accessing the corresponding communication quality data processing result memory.

[0031] Optionally in this embodiment, the task boundary constraints are information describing the motion boundary restrictions received by the ROV when performing a task, including but not limited to the entry area boundary, the robotic arm posture boundary, the docking inspection boundary, the safety boundary margin, the thrust boundary, and the safety boundary, etc., which are collected and stored in the corresponding task boundary constraint result memory through manual input or automated parameter acquisition; in this embodiment, the sensing module obtains the corresponding task boundary constraints by accessing the corresponding task boundary constraint result memory.

[0032] In this embodiment, multi-sensor observation data, communication quality data, device health data, and task boundary constraints are packaged into a structured raw data packet and stored in a corresponding storage unit. This allows other modules that need to use this data to quickly locate the required data type and content from the raw data packet.

[0033] The fusion estimation module is used to process the multi-sensor observation data and communication quality data of ROV using a fusion algorithm to obtain fused data.

[0034] In this embodiment, before processing with the fusion algorithm, the fusion estimation module can further perform time alignment based on timestamps and coordinate unification based on coordinate system identifiers for multi-sensor observation data from different sensors, specifically combining multi-sensor observation data with latency data in the communication quality data. This is done by combining sensor health indicators and / or observation quality scores to remove abnormal data and perform confidence gating. Optionally, in this embodiment, if the confidence score of an observation quality score for a sensor is less than a set confidence gating threshold, the fusion weight of the corresponding sensor can be reduced during subsequent fusion algorithm processing. If necessary, the control generation module can downgrade the ROV's autonomy level accordingly.

[0035] In this embodiment, the fusion algorithm can employ one or more of the following combinations: factor graph optimization, sliding window optimization, extended Kalman filtering, unscented Kalman filtering, particle filtering, robust M-estimation, graph optimization and filtering hybrid structure, neural network-assisted fusion, etc. After processing by the fusion algorithm, the output fused data includes, but is not limited to, ROV state estimates, positioning uncertainty, sensor confidence, sensor availability, time delay correction, extrinsic parameter correction, etc.

[0036] In this embodiment, the fused data is packaged into a structured fused data packet and stored in a corresponding storage unit, so that other modules that need to use the fused data can quickly locate the required data type and data content from the fused data packet.

[0037] The control generation module is used to generate candidate control variables by performing control optimization processing based on the fused data, the ROV's equipment health data, and the boundary constraints of the tasks performed by the ROV.

[0038] In this embodiment, the control optimization process includes: (a) Calculate the ROV's comprehensive operational risk score based on one or more of the following: fused data, equipment health data, and task boundary constraints, and then determine the ROV's autonomy level; (b) Generate basic control quantities based on the minimum control algorithm; generate optimized control quantities based on the optimization control algorithm; generate compensation quantities based on the learning reinforcement algorithm; (c) Based on the ROV's comprehensive operational risk score and ROV autonomy level, data arbitration is conducted on one or more of the basic control variables, optimized control variables, and compensation variables to form candidate control variables.

[0039] In this embodiment, when calculating the ROV's comprehensive operational risk score, optionally, a weighted summation can be performed based on the normalized values ​​of positioning uncertainty, thruster failure probability (obtainable through current residual, speed residual, temperature rise model, vibration model, power efficiency, or multi-residual voting), communication link quality, safety boundary margin, and the historical trigger frequency of the containment module triggering safety constraint filtering. The weights of each item in the weighted summation are set to configurable weights. The historical trigger frequency of the containment module triggering safety constraint filtering can be statistically analyzed by the log evidence module based on recorded safety constraint filtering history and then fed back to the control generation module. In other embodiments, the ROV's comprehensive operational risk score can also be calculated using fuzzy logic, Bayesian networks, Markov models, learning-based risk assessors, expert rules, multi-level thresholds, etc.

[0040] In this embodiment, optionally, the control generation module, in addition to calculating the ROV's comprehensive operational risk score, can further calculate and evaluate the current ROV autonomy level, constraint tightening parameters, control algorithm enable weights, and ROV degrade warning flags. The constraint tightening parameters are used to convert constraints such as minimum obstacle distance, minimum ground clearance, maximum speed, attitude angle, and thruster current limit from the ROV's mission nominal values ​​to current operating values. The control algorithm enable weights are used to limit the participation weight of the outputs of the safety control algorithm, optimization control algorithm, and learning reinforcement algorithm during data arbitration. The ROV's comprehensive operational risk score, ROV autonomy level, constraint tightening parameters, control algorithm enable weights, and ROV degrade warning flags can be packaged together into a structured risk data package and stored in corresponding storage units. This allows other modules that need to use this data to quickly locate the required data type and content from the risk data package.

[0041] In this embodiment, the optional safety control algorithm can be PID, robust control, adaptive control, sliding mode control, backstepping control, disturbance observer control, LOS guidance control, etc.; the optimization control algorithm can be MPC, energy / benefit optimization MPC, nonlinear MPC, model predictive path integral control, constrained optimal control, etc.; and the learning enhancement algorithm can be DRL, DeePC, PINN, neural network hydrodynamic model, Gaussian Process compensator, safety supervised learning model, etc. In addition to the compensation amount, the output of the learning enhancement algorithm can also include one or more of the following: model residual, cost function weight, feasible region boundary, and desired trajectory correction, and it is not used as the basis for directly driving the thruster. Optionally, the learning enhancement algorithm can set corresponding learning strategies based on historical data, current data, and the ROV's mission environment.

[0042] In other embodiments, when performing control optimization processing, in addition to arbitrating the basic control quantity, optimized control quantity, and compensation quantity based on the ROV's comprehensive operational risk score and ROV autonomy level, data arbitration can also be carried out by introducing ROV's task setting trajectory information, etc., to ensure that the arbitration result does not deviate from the task that the ROV needs to perform.

[0043] Optionally in this embodiment, when arbitrating data on basic control quantities, optimized control quantities, and compensation quantities based on the ROV's comprehensive operational risk score and ROV autonomy level, the data arbitration also includes at least the following specific content corresponding to the ROV autonomy level: sensor confidence level and communication link quality. The content of the data arbitration includes: when the ROV's comprehensive operational risk score is relatively low (with a high score representing high risk), and the sensor confidence level and communication link quality are reliable (whether reliable depends on whether the sensor confidence level and communication link quality are below the corresponding set threshold), the proportion of optimized control quantities and compensation quantities in the candidate control quantities can be increased; when the ROV's comprehensive operational risk score increases, and the sensor confidence level or communication link quality is low, the data arbitration also includes the following: When the link quality is unreliable, the optimized control and compensation quantities are reduced or masked, retaining only the basic control quantities, and the ROV autonomy level is downgraded. When the ROV's overall operational risk score decreases, the sensor confidence level recovers to a reliable level, and the communication link quality recovers, the lower ROV autonomy level can be gradually restored to a higher ROV autonomy level. To avoid frequent jitter, the switching of the ROV autonomy level can be set with a state machine composed of one or more state conditions such as hysteresis threshold, minimum hold time, and manual confirmation conditions. Information such as communication link quality, multi-sensor observation data quality, and thruster health is incorporated into the selected control mode to reduce the safety risks caused by remote control operation delays and underwater environmental uncertainties.

[0044] Optionally in this embodiment, the output after data arbitration may include, in addition to the candidate control quantity, one or more of the following: control source identifier, prediction state, nominal constraint margin, and candidate feasibility flag. Optionally in this embodiment, the candidate control quantity may be packaged into a structured candidate data packet and stored in a corresponding storage unit, thereby facilitating other modules that need to use this data to quickly locate the required data type and content from the candidate data packet. In other embodiments, one or more of the following may also be packaged into the candidate data packet simultaneously: control source identifier, prediction state, nominal constraint margin, and candidate feasibility flag.

[0045] The safe containment module is used to perform safety constraint filtering on candidate control variables to obtain safe control variables.

[0046] In this embodiment, the safety constraint filtering process includes: directly using candidate control quantities that satisfy the safety constraints as safety control quantities, performing the closest safety control solution on candidate control quantities that do not satisfy the safety constraints, and generating a safety control quantity that satisfies the safety constraints and has the smallest deviation from the candidate control quantities.

[0047] Optionally in this embodiment, based on the ROV state estimate, ROV comprehensive operational risk score, ROV constraint set, positioning uncertainty, action boundaries of the motion execution devices in the ROV, and control law boundaries of the ROV remote control station, a quadratic programming problem (QP) solution method based on the combined constraints of control Lyapunov function (CLF) and control obstacle function (CBF) is used to solve the candidate control variables to obtain the safe control variables. The ROV constraint set may include, but is not limited to, maximum depth, minimum height above the bottom, minimum obstacle distance, maximum attitude angle, maximum angular velocity, maximum speed, cable tension, upper limit of current, upper limit of temperature, and battery SOC. The constraints can be one or more of the following: upper limit of communication latency, restricted area boundary, and robot arm posture boundary; the ROV constraint set can be selected from multi-sensor observation data, communication quality data, equipment health data, and task boundary constraints, or it can be selected from the performance parameters of the ROV itself; in this embodiment, optionally, one or more combinations of CBF safety constraints, CLF stability constraints, execution device saturation constraints, control rate of change constraints, and task boundary constraints can be used as the corresponding safety constraints; CBF safety constraints are used to keep the forward direction of various ROV states unchanged, and CLF stability constraints are used to keep the ROV converging towards the desired trajectory or conservative hovering point.

[0048] In this embodiment, the optional calculation method for generating the safe control quantity with the smallest deviation from the candidate control quantity can be to introduce a slack variable (representing a quantity that can have safety redundancy) for weighted summation based on the interval constraints between each candidate control quantity and the optional control quantity that meets the corresponding safety constraints. The term with the smallest weighted summation result is selected, and the optional control quantity that meets the corresponding safety constraints corresponding to this term is taken as the corresponding safe control quantity. The optional control quantity is obtained from solving the quadratic programming problem.

[0049] In other embodiments, the closest solution to the safety control can also be achieved by second-order cone programming, linear programming, control invariant set, reachability set analysis, model predictive safety filter, combination of barrier function and saturation function, regular safety filter, etc., as long as it can realize the real-time checking and trimming of candidate control variables to safety control variables that meet the underwater safety boundary.

[0050] Optionally, in this embodiment, if the safety constraint filtering process fails or the closest safety control solution times out, the safety shell module can directly output a command to perform a single or continuous downgrade of the ROV's autonomy level. This ensures that the ROV can execute preset mission exit strategies such as conservative hovering, cable retraction, deceleration cruise, surfacing, reducing maximum speed, tightening attitude angle limits, switching to constant depth and attitude, and retraction along a preset safety direction. Even if the output of the learning reinforcement algorithm is abnormal, the last command executed can still meet the constraints of the safety boundary. Safety constraint filtering failure takes precedence over other risk increases. Insufficient safety boundary margins such as collisions, bottoming out, and depth take precedence over communication link quality degradation. Thruster failure probability takes precedence over sensor availability. When outputting commands to perform single or continuous downgrades of the ROV's autonomy level, the command must provide information such as the required ROV autonomy level to be downgraded to, mission exit strategy type, temporary constraints such as maximum speed / maximum thrust / attitude angle, minimum hold time, and recovery conditions, based on priority. The command can directly override candidate control variables or directly trigger conservative hovering. In the next ROV control cycle, it serves as a reference for the control generation module to generate basic control variables, optimized control variables, and compensation variables to prevent frequent switching of the ROV's control mode.

[0051] Optionally in this embodiment, the safety control quantity can be packaged into a structured safety control data packet and stored in a corresponding storage unit, so that other modules that need to use this data can quickly locate the required data type and data content from the safety control data packet. In other embodiments, information such as the active ROV constraint set, slack variable terms, quadratic programming problem solution status, control quantity deviation, whether the closest safe control solution has timed out, and whether the closest safe control solution is infeasible can also be packaged into the safety control data packet.

[0052] The thruster action generation module is used to obtain the ROV's thruster action commands by processing the propulsion power allocation based on safety control quantities and equipment health data.

[0053] In this embodiment, the propulsion power distribution includes: generating a propulsion action matrix corresponding to multiple propellers based on safety control quantities, performing output distribution control processing on the propulsion action matrix based on equipment health data, and forming a propulsion action command that adjusts the power output of each of the multiple propellers.

[0054] Optionally in this embodiment, when distributing propulsion power, the available thrust boundary of the thruster can be combined with safety control quantities to generate the thruster action matrix.

[0055] In this embodiment, the selected equipment health data may include, but is not limited to, one or more of the following: thruster failure probability, thruster efficiency, temperature limit, current limit, and set action command change rate. The output allocation control processing can update the thrust weight and available thrust boundary of each thruster in the thruster action matrix according to the thruster failure probability to achieve soft switching. For example, when the failure probability of a certain thruster increases, the thrust weight and maximum thrust allocated to that thruster are reduced, and the remaining control requirements are smoothly allocated to other thrusters. In other embodiments, the output allocation control processing may also use pseudo-inverse allocation, quadratic programming allocation, or priority allocation to perform soft switching.

[0056] Optionally in this embodiment, the content of the thruster action command may include the thrust and control surface direction of the thruster, converting the safety control quantity into corresponding thrust and control surface data to construct a thruster action matrix.

[0057] Optionally in this embodiment, the thruster action command, allocation residual, saturation flag, derating ratio, and execution confirmation status can be packaged into a structured adjustment data package and stored in a corresponding storage unit. The information in the adjustment data package can also serve as part of the health data for the next control cycle of the ROV, thus forming a health diagnosis closed loop. When the probability of thruster failure increases but does not reach the point where complete shutdown is required, the thruster action generation module gradually reduces the available thrust weight of the thruster according to the corresponding output allocation processing method, thereby achieving smooth thrust derating adjustment before the thruster may fail.

[0058] The log evidence module is used to record data in a structured manner.

[0059] In this embodiment, the structured content recorded by the log evidence module may include, but is not limited to, original observation summaries, candidate control variables, safety control variables, closest safety control solutions, ROV autonomy level changes, failure probabilities, control optimization strategies, operator inputs, manual takeover records, hash digests, etc. When recording structured data, it is encrypted using a hash chain to form an evidence package, which can be stored in tamper-proof storage such as the ROV itself, deck station, or remote cloud. In other embodiments, the evidence package may also employ digital signatures, trusted clocks, blockchain ledgers, or read-only event logs. The evidence package fields can be extended to include candidate control variables, safety control variables, various constraints, and other information.

[0060] Optionally in this embodiment, after recording data, the log evidence module counts the frequency at which the closest safety control solution is triggered during the safety constraint filtering process. This frequency is used as the historical trigger frequency of the safety constraint filtering triggered by the safe shell module and fed back to the control generation module for calculating the ROV comprehensive operational risk score.

[0061] Optionally in this embodiment, the log evidence module organizes data records from multiple ROV control cycles into a replayable evidence package, which can be used for offline playback, SIL / HIL fault injection, and shadow mode comparison processes. The shadow mode allows thruster action commands to be executed in the actual task only after the verification indicators meet the requirements of the ROV simulation simulator and the version is locked. The log evidence module provides a data foundation for post-task accident analysis, parameter regression, and certification review.

[0062] To further illustrate the feasible implementation methods of this application, a specific implementation example is given below using a typical underwater pipeline inspection scenario. This implementation example is only used to illustrate the data transfer and security control process between some modules and does not constitute a limitation on the scope of protection of this application.

[0063] In the underwater pipeline inspection scenario, closed-loop control is executed with a control cycle of 100ms. During the current control cycle, the sensing module acquires multi-sensor observation data, communication quality data, equipment health data, and task boundary constraints. The multi-sensor observation data includes DVL velocity v_dvl=(0.18,0,-0.02)m / s, INS attitude (φ,θ,ψ)=(1.5°,-0.8°,-90°), depth gauge depth d=118.6m, and the nearest obstacle distance d_obs=1.85m measured by the forward-looking sonar. The communication quality data includes one-way delay τ=4... The data was obtained with a 5ms response time, a packet loss rate of 0.6%, and a communication link quality of Q_link=0.994. The equipment health data included the current of the 6 thrusters I=[6.3,6.1,6.4,6.2,6.3,6.2], temperature rise of less than 20K, and failure probability P_fault=[0.03,0.02,0.04,0.02,0.03,0.02]. The task boundary constraints included the minimum obstacle distance d_min=1.2m and the minimum height above the bottom h_min=0.8m.

[0064] After performing time alignment, coordinate unification, and confidence gating on the aforementioned multi-source data, the fusion estimation module uses sliding window optimization with a tight coupling factor graph for fusion estimation. The window length is 100ms, yielding the fused position p_hat=(x,y,z)=(32.410m,-12.057m,-119.0m), the positioning covariance Σ_p=diag(0.022,0.018,0.031)m², the position standard deviation σ_pos=0.17m, and the sensor confidence vector γ=[0.92,0.88,0.97]. The fusion estimation module packages the aforementioned state estimates, positioning uncertainty, and sensor confidence into a fusion data package for subsequent use by the control generation module and the containment module.

[0065] The control generation module calculates the comprehensive operational risk score of the ROV based on the fused data, equipment health data, and task boundary constraints. The risk score can be calculated using the following formula: R=w1·(σ_pos / 0.5)+w2·P_fault_avg+w3·(τ / 0.5)+w4·(1-Q_link) In the formula, τ is in seconds, P_fault_avg is the average failure probability of the six thrusters, and w1, w2, w3, and w4 are configurable weights. In this example, (w1, w2, w3, w4) = (0.40, 0.05, 0.30, 0.25), P_fault_avg = 0.0267, and τ = 0.045s. Substituting these values ​​into the formula, we get R ≈ 0.17. Since R is in the low-risk range, if the communication link quality and sensor confidence meet the threshold requirements, the control generation module determines the current ROV autonomy level to be L2 supervised autonomy.

[0066] Under L2 supervised autonomy, the control generation module generates basic control variables, optimized control variables, and learning compensation variables. Taking a set six-degree-of-freedom generalized control variable [Fx,Fy,Fz,Mx,My,Mz] as an example, the basic control variable is F_pid=(28,0,-14,0,0,0), the optimized control variable is F_mpc=(25,-2,-15,0.6,0.4,-0.5), and the learning compensation variable is ΔF_pinn=(2,0.5,-1,0,0,0.2), where the first three terms are in N and the last three terms are in N·m.

[0067] The control generation module arbitrates the aforementioned basic control quantity, optimized control quantity, and learning compensation quantity. The arbitration formula can be expressed as: F_cand=α·F_pid+(1-α)·(F_mpc+k·ΔF_pinn) In this example, α=0.45 and k=0.5, resulting in the candidate control quantity F_cand=(26.90,-0.96,-14.83,0.33,0.22,-0.22). This candidate control quantity does not directly drive the thruster, but is instead input into the containment module for safety constraint filtering.

[0068] The containment module constructs safety constraints based on the fusion location, the distance to the nearest obstacle, the height above the bottom, and the mission boundary constraints. Taking obstacle constraints as an example, the obstacle control function can be expressed as h_obs = d_obs - d_min; taking bottom-height constraints as an example, the obstacle control function can be expressed as h_bottom = h_bottom_real - h_min, where h_bottom_real is the current height above the bottom. In this example, h_obs = 1.85m - 1.2m = 0.65m and h_bottom = 1.30m - 0.8m = 0.50m are both greater than 0, indicating that the current state is still within the safety constraints.

[0069] The containment module further constructs a quadratic programming problem, min||F_safe-F_cand||²+ρ·s², with the objective of minimizing the deviation of the candidate control variables. It then solves for the safe control variable F_safe under constraints of the control obstacle function, maximum velocity, attitude angle, thruster current, and control rate of change, where s is a relaxation variable and ρ is the relaxation penalty coefficient. Since the candidate control variables satisfy the safety constraints within this control cycle, the quadratic programming solution yields F_safe=F_cand, indicating that pruning filtering was not triggered in this round. If d_obs decreases to near the safety threshold in the next control cycle, the containment module can automatically reduce the control component towards the obstacle, ensuring the output still satisfies the safety constraints.

[0070] The thruster motion generation module allocates propulsion power based on safety control parameters and equipment health data. Taking a symmetrical layout of 6 thrusters as an example, let the thruster allocation matrix be A, and the health weight matrix be W=diag(1-P_fault); the thruster thrust vector Q can be solved using the following health-weighted pseudo-inverse: Q=W·A T ·(A·W·A T +λI) -1 ·F_safe In the formula, λ is the regularization coefficient to prevent matrix ill-conditioning. In this example, the upper limit of thrust of each thruster is taken as 40N. Substituting into the above formula, the thruster action command Q=[24.8,23.9,25.2,24.1,24.8,24.0] is obtained. The thrust of each thruster does not exceed the limit. At the same time, since the failure probability of the third thruster is relatively high, its health weight is relatively low. The thruster action generation module can smoothly reduce its thrust in subsequent control cycles and allocate the remaining control requirements to other thrusters.

[0071] The log evidence module records the structured inputs, outputs, and intermediate processing results of each module within the same control cycle. For example, the log content may include "t=1742.6s, R=0.17, Autonomy=L2, F_cand=[26.90,-0.96,-14.83,0.33,0.22,-0.22], F_safe=[26.90,-0.96,-14.83,0.33,0.22,-0.22], T=[24.8,23.9,25.2,24.1,24.8,24.0], CBF_satisfied=true, Hash=7F2A", etc. This log can be used for task replay, fault reproduction, shadow mode verification, and compliance audits.

[0072] As can be seen from the above example, the perception module provides raw state, communication, health and task boundary information, the fusion estimation module forms a reliable state estimate, the control generation module generates candidate control variables and determines the ROV autonomy level, the safe shell module performs safety constraint filtering on the candidate control variables, the thruster action generation module generates the final thruster action command, and the log evidence module synchronously saves the evidence chain, thus forming a practically implementable ROV safety control closed loop.

[0073] Compared with the prior art, the advantages of this application are as follows: By passing candidate control variables through the containment module, abnormal outputs are prevented from directly driving the ROV's thrusters, improving safety in high-risk underwater scenarios. Health status and communication quality are integrated for control mode switching, eliminating reliance on single threshold alarms and allowing the ROV to select appropriate control variables based on actual operational risks. Using ROV health status for thrust allocation reduces control abrupt changes compared to binary fault approaches, improving the ability to continue mission execution even in situations of thruster degradation, entanglement, stall precursors, or abnormal temperature rise. Structured recording of various data during control facilitates fault reproduction and regulatory review. It is compatible with different autonomy levels, including direct manual control, shared control, and supervised autonomy, meeting the needs of inspection-level ROVs, operational ROVs, ROVs with robotic arms, resident ROVs, and underwater gliders. Through the connection between module inputs and outputs, ROV status, health, communication, mission constraints, risk scores, candidate controls, safety controls, executed commands, and autonomy level strategies are transmitted within the same data loop, preventing independent processing by individual modules and ensuring ROV safety.

[0074] like Figure 2 As shown in the figure, this application discloses a ROV safety control method, which includes the following steps.

[0075] S1. Acquire multi-sensor observation data, communication quality data, equipment health data, and task boundary constraints.

[0076] S2. The multi-sensor observation data and communication quality data of the ROV are processed using a fusion algorithm to obtain fused data.

[0077] S3. Based on the fused data, ROV equipment health data, and the boundary constraints of the tasks performed by the ROV, perform control optimization processing to generate candidate control variables.

[0078] S4. Perform safety constraint filtering on the candidate control variables to obtain the safety control variables.

[0079] S5. Based on safety control parameters and equipment health data, perform propulsion power distribution processing to obtain ROV thruster action commands.

[0080] S6. When executing steps S1 to S5, the data is recorded in a structured manner during the execution of each step.

[0081] The methods described above are executed based on the corresponding ROV safety control systems in the foregoing embodiments and have the beneficial effects of the corresponding system embodiments, which will not be repeated here.

[0082] like Figure 3 As shown, based on the same inventive concept and corresponding to the methods of the above embodiments, this application also discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the above-described ROV safety control method.

[0083] Specifically, the device includes: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected within the device via the bus 1050.

[0084] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), GPU (Graphics Processing Unit), or one or more integrated circuits, to implement relevant programs and achieve the technical solutions provided in the embodiments of this specification.

[0085] The memory 1020 can be implemented in the form of ROM (Read-Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1020 and called by the processor 1010. The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, projectors, speakers, vibrators, indicator lights, etc.

[0086] The communication interface 1040 is used to connect the communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB (Universal Serial Bus), network cable, etc.) or wireless means (such as mobile network, WIFI (Wireless Fidelity), Bluetooth, etc.).

[0087] Bus 1050 includes an information path for transmitting information between various components of the device (e.g., processor 1010, memory 1020, input / output interface 1030, and communication interface 1040).

[0088] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0089] The electronic devices described above are used to implement the corresponding ROV safety control methods in the foregoing embodiments and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0090] Based on the same inventive concept, corresponding to the ROV safety control method in the above embodiments, this application also discloses a computer-readable storage medium that stores computer instructions for causing a computer to implement the ROV safety control method as described above.

[0091] The computer-readable storage medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium, which can be used to store information accessible by a computing device. The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to implement the ROV safety control method as described in the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0092] The above description is merely a preferred embodiment and the technical principles employed in this application. This application is not limited to the specific embodiments or combinations thereof, and various obvious changes, readjustments, and substitutions that can be made by those skilled in the art will not depart from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments, and may include more other equivalent embodiments without departing from the concept of this application, the scope of which is determined by the scope of the claims.

Claims

1. A ROV safety control system, characterized in that, include: The fusion estimation module is used to process the multi-sensor observation data and communication quality data of the ROV using a fusion algorithm to obtain fused data; The control generation module is used to generate candidate control quantities by performing control optimization processing based on the fused data, the ROV's equipment health data, and the boundary constraints of the tasks performed by the ROV. The safe shell module is used to perform safety constraint filtering on the candidate control variables to obtain safe control variables; The thruster action generation module is used to obtain the ROV's thruster action commands by performing propulsion power distribution processing based on the safety control variables and equipment health data.

2. The ROV safety control system according to claim 1, characterized in that, It also includes a sensing module; The perception module is used to acquire the multi-sensor observation data, the communication quality data, the device health data, and the task boundary constraints.

3. The ROV safety control system according to claim 1, characterized in that, It also includes a log evidence module; The log evidence module is used to record data in a structured manner.

4. The ROV safety control system according to claim 1, characterized in that, Before processing with the fusion algorithm, the following is also included: Based on multi-sensor observation data and communication quality data, time alignment, coordinate unification, and confidence gating are performed on the multi-sensor observation data.

5. The ROV safety control system according to claim 1, characterized in that, The control optimization process includes: The ROV's comprehensive operational risk score is calculated based on one or more of the following: fused data, equipment health data, and task boundary constraints. Then, the ROV's autonomy level is determined. Basic control quantities are generated based on a minimum control algorithm; Optimized control quantities are generated based on optimized control algorithms; Compensation amounts are generated based on learning-enhanced algorithms; Based on the ROV's comprehensive operational risk score and its autonomy level, data arbitration is performed on one or more of the basic control variables, optimized control variables, and compensation variables to form candidate control variables.

6. The ROV safety control system according to claim 1, characterized in that, The security constraint filtering process includes: Candidate control variables that satisfy safety constraints are directly used as safety control variables; For candidate control quantities that do not meet the safety constraints, perform the closest safety control solution to generate a safety control quantity that meets the safety constraints and has the smallest deviation from the candidate control quantity.

7. The ROV safety control system according to claim 1, characterized in that, The propulsion power distribution includes: Generate a thruster action matrix corresponding to multiple thrusters based on the safety control parameters; Based on the equipment health data, the output distribution control process of the thruster action matrix is ​​performed to generate thruster action commands that adjust the power output of each of the multiple thrusters.

8. A ROV safety control method, executed based on the ROV safety control system according to any one of claims 1-7, characterized in that, include: The multi-sensor observation data and communication quality data of ROV are processed using a fusion algorithm to obtain fused data; Based on the fused data, ROV device health data, and the task boundary constraints performed by the ROV, control optimization processing is performed to generate candidate control variables; The candidate control variables are subjected to safety constraint filtering to obtain the safe control variables; Based on the safety control parameters and equipment health data, propulsion power distribution processing is performed to obtain the ROV's thruster action commands.

9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement the ROV safety control method of claim 8.

10. A storage medium, which is a computer-readable storage medium, characterized in that, The device stores computer instructions for causing the computer to implement the ROV safety control method of claim 8.