A control method and device of a vehicle driving assistance system, a vehicle, and a medium

CN122830728APending Publication Date: 2026-09-29HUIZHOU DESAY SV AUTOMOTIVE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611273706.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-21
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0004]然而,ODD的二元判定导致功能行为突兀,功能以全权运行直至硬ODD边界被突破后突然中断并将控制权交还驾驶员,而驾驶员可能无法及时接管

Benefits of technology

[0010]本发明实施例的技术方案,通过获取车辆的感知数据、传感器健康诊断数据和环境数据;根据感知数据、传感器健康诊断数据及环境数据,确定风险参数;根据风险参数,确定动态安全包络的尺寸及车辆驾驶辅助系统当前允许的权限级别;根据动态安全包络的尺寸和当前允许的权限级别,对车辆驾驶辅助系统进行控制。通过感知置信度值、环境严重度估计值和道路使用者风险值中的至少一项驱动动态安全包络自适应缩放和权限级别分级递降,实现了从全权限运行到完全退出的平滑过渡,避免了功能突然中断、传感器过度信任或不必要禁用等问题,同时防止了权限在阈值附近振荡。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122830728A_ABST
    Figure CN122830728A_ABST
Patent Text Reader

Abstract

The application discloses a control method and device of a vehicle driving assistance system, a vehicle and a medium, and relates to the technical field of vehicle driving assistance systems. The method comprises the following steps: acquiring sensing data, sensor health diagnosis data and environment data of a vehicle; determining a risk parameter according to the sensing data, the sensor health diagnosis data and the environment data; determining the size of a dynamic safety envelope and the current permission level allowed by the vehicle driving assistance system according to the risk parameter; and controlling the vehicle driving assistance system according to the size of the dynamic safety envelope and the current permission level. At least one of the sensing confidence value, the environment severity estimation value and the road user risk value is used to drive adaptive scaling of the dynamic safety envelope and hierarchical degradation of the permission level, smooth transition from full permission operation to complete exit is realized, problems such as sudden function interruption, excessive sensor trust or unnecessary disablement are avoided, and oscillation of the permission around a threshold value is prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle technology, and in particular to a control method, device, vehicle, and medium for a vehicle driving assistance system. Background Technology

[0002] Advanced Driver Assistance Systems (ADAS) functions such as Adaptive Cruise Control (ACC), Lane Centering Control (LCC), Highway Guidance, Traffic Jam Assist, and Automated Parking are all designed to operate within a defined Operational Design Domain (ODD). The ODD specifies the set of conditions, including road types, speed ranges, weather, lighting, and traffic conditions, under which the function design can function.

[0003] Traditional systems treat ODD membership relationships as a binary decision: a function can be in an available or unavailable state and uses a fixed, design-phase calibrated safety margin / safety zone, such as a fixed following time interval and a fixed geometric buffer zone around the vehicle. Specifically, when the system determines that the current scene parameters meet the ODD conditions, the function runs with full permissions; when any scene parameter exceeds the ODD boundary, the function is determined to be unavailable and abruptly terminated, at which point control is returned to the driver.

[0004] However, the binary decision-making of the ODD leads to abrupt functional behavior. Functions operate with full authority until the hard ODD boundary is breached, at which point they abruptly terminate and hand control back to the driver, who may not be able to take over in time. When pedestrians, cyclists, or road workers are detected, system permissions remain at normal levels until passive emergency braking or path planning avoidance is triggered, causing safety boundary tightening to lag behind risk escalation. Function permissions can only switch between full-authority operation and complete exit; when a change in risk is perceived, the risk level cannot be mapped to the corresponding permission level, causing function permissions to jump abruptly. Summary of the Invention

[0005] This invention provides a control method, device, vehicle, and medium for a vehicle driving assistance system, to achieve adaptive scaling of the dynamic safety envelope and hierarchical changes in permission levels.

[0006] According to a first aspect of the present invention, a control method for a vehicle driving assistance system is provided, comprising: Acquire vehicle perception data, sensor health diagnostic data, and environmental data; Based on the perceived data, the sensor health diagnostic data, and the environmental data, risk parameters are determined, including at least one of the perceived confidence value, the environmental severity estimate, and the road user risk value. Based on the risk parameters, the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system are determined. The permission level includes multiple restricted levels, and each restricted level corresponds to a set of functional permission restrictions. The vehicle driving assistance system is controlled based on the size of the dynamic safety envelope and the currently permitted permission level.

[0007] According to a second aspect of the present invention, a control device for a vehicle driving assistance system is provided, comprising: The data acquisition module is used to acquire vehicle perception data, sensor health diagnostic data, and environmental data; The parameter determination module is used to determine risk parameters based on the perception data, the sensor health diagnosis data, and the environmental data. The risk parameters include at least one of the perception confidence value, the environmental severity estimate, and the road user risk value. The level determination module is used to determine the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system based on the risk parameters. The permission level includes multiple restricted levels, and each restricted level corresponds to a set of functional permission restrictions. The system control module is used to control the vehicle driving assistance system according to the size of the dynamic safety envelope and the currently allowed permission level.

[0008] According to a third aspect of the present invention, a vehicle is provided, the vehicle comprising: At least one controller; and A memory communicatively connected to the at least one controller; wherein, The memory stores a computer program that can be executed by the at least one controller, which enables the at least one controller to perform the control method of the vehicle driving assistance system according to any embodiment of the present invention.

[0009] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a controller to execute and implement the control method of the vehicle driving assistance system according to any embodiment of the present invention.

[0010] The technical solution of this invention acquires vehicle perception data, sensor health diagnostic data, and environmental data; determines risk parameters based on the perception data, sensor health diagnostic data, and environmental data; determines the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system based on the risk parameters; and controls the vehicle driving assistance system based on the size of the dynamic safety envelope and the currently allowed permission level. By driving the dynamic safety envelope to adaptively scale and the permission level to progressively decrease through at least one of the perception confidence value, environmental severity estimate, and road user risk value, a smooth transition from full-permission operation to complete exit is achieved, avoiding problems such as sudden function interruption, excessive sensor trust, or unnecessary sensor disabling, while also preventing permission oscillations around thresholds.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of a control method for a vehicle driving assistance system according to Embodiment 1 of the present invention; Figure 2 This is a schematic diagram illustrating the risk-authority mapping relationship of a control method for a vehicle driving assistance system according to Embodiment 1 of the present invention. Figure 3 This is a flowchart of a control method for a vehicle driving assistance system according to Embodiment 2 of the present invention; Figure 4 This is a schematic diagram of the dynamic safety envelope of a control method for a vehicle driving assistance system according to Embodiment 2 of the present invention; Figure 5 This is a schematic diagram of the structure of a control device for a vehicle driving assistance system according to Embodiment 3 of the present invention; Figure 6 This is a structural schematic diagram of a vehicle that implements an embodiment of the present invention. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] Example 1 Figure 1 This is a flowchart illustrating a control method for a vehicle driving assistance system according to Embodiment 1 of the present invention. This embodiment is applicable to the control of vehicle driving assistance systems. The method can be executed by a control device for the vehicle driving assistance system, which can be implemented in hardware and / or software and can be configured in a vehicle. Figure 1 As shown, the method includes: S110: Acquire vehicle perception data, sensor health diagnostic data, and environmental data.

[0017] In this embodiment, perception data refers to the raw or pre-processed perception information collected by the vehicle's onboard sensors. For example, onboard sensors include cameras, millimeter-wave radar, and lidar, used to detect obstacles, lane markings, road users, and other information around the vehicle. Sensor health diagnostic data refers to the status monitoring information of each sensor itself. This includes, but is not limited to, the field-of-view occlusion rate of each sensor (e.g., the proportion of a camera lens obscured by dirt), the deviation between the effective detection distance and the nominal value, the signal-to-noise ratio, data interruption rate, calibration drift estimate, frame / echo interruption rate, self-test status, and delay / time synchronization error. This health diagnostic data can be provided by the sensor's built-in self-diagnostic function or an independent health monitoring module. Environmental data refers to information characterizing the external environmental conditions of the vehicle. Environmental data includes at least one of precipitation rate, visibility distance, road friction coefficient, and lighting intensity. Environmental data can come from the vehicle's onboard sensors (such as rain sensors and light sensors), or can be obtained from roadside equipment or surrounding vehicles via V2X communication, or from cloud data services for weather forecasts or road friction coefficient information for the vehicle's current location.

[0018] Specifically, the controller can acquire perception data collected by the vehicle's onboard sensors, as well as status monitoring information from each sensor, to form sensor health diagnostic data. The controller can also acquire environmental data in real time through onboard sensors, or via V2X communication or cloud data.

[0019] S120. Based on the sensing data, sensor health diagnostic data, and environmental data, determine the risk parameters.

[0020] In this embodiment, the risk parameters are a set of parameters that quantify the comprehensive risks currently faced by the vehicle. These risk parameters include at least one of the following: perception confidence value, environmental severity estimate, and road user risk value. The perception confidence value is a quantitative representation of the reliability of the perception system's output. The environmental severity estimate is the result of a quantitative assessment of the degree of danger in the external environment in which the vehicle is located. The road user risk value is the result of a quantitative assessment of the risks arising from the presence of vulnerable road users around the vehicle.

[0021] Specifically, the controller can normalize the various health indicators of each sensor to obtain an availability score, and then combine the availability scores of multiple sensors to generate a perception confidence value. The controller can generate an environmental severity estimate based on at least one of the following environmental data: precipitation rate, visibility distance, road friction coefficient, and lighting intensity. The controller can generate a road user risk value based on road user information detected in the perception data and combined with information on densely populated areas at the vehicle's current location (e.g., school district information, workplace information, zebra crossing information, and bus stop information).

[0022] For example, the perceived confidence value is C, the environmental severity estimate is E, and the road user risk value is H, forming a fused risk parameter R = f(E, 1-C, v, H), where v is the vehicle speed and f is a calibrable monotonic function.

[0023] S130. Based on the risk parameters, determine the size of the dynamic safety envelope and the currently permitted permission level of the vehicle's driver assistance system.

[0024] In this embodiment, the dynamic safety envelope refers to the dynamically changing safety space boundary around the vehicle, the size of which is jointly defined by the safety margins at the front, rear, and lateral sides of the vehicle. The permission level refers to the level of functional permission that the vehicle's driver assistance system is currently allowed to execute. The permission level includes multiple restricted levels, each corresponding to a set of functional permission restrictions.

[0025] Specifically, the controller can calculate the safety margins in each direction based on the driving conditions of its own vehicle and other vehicles. Furthermore, by incorporating risk parameters, it dynamically expands or shrinks the safety margins in the corresponding directions to obtain a dynamic safety envelope. The controller can determine the sensor health restriction level based on the perception confidence value, the environmental restriction level based on the environmental severity estimate, and the personnel presence restriction level based on the road user risk value. Finally, it arbitrates based on each permission dimension to determine the currently permitted permission level.

[0026] S140. Control the vehicle driver assistance system based on the size of the dynamic safety envelope and the currently permitted permission level.

[0027] Specifically, the controller can use the dynamic safety envelope as a hard constraint for the vehicle's motion planning, controlling the vehicle's trajectory to not exceed the boundary of the dynamic safety envelope, while restricting the execution authority of the vehicle's driver assistance system according to the currently allowed permission level.

[0028] The technical solution of this invention acquires vehicle perception data, sensor health diagnostic data, and environmental data; determines risk parameters based on the perception data, sensor health diagnostic data, and environmental data; determines the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system based on the risk parameters; and controls the vehicle driving assistance system based on the size of the dynamic safety envelope and the currently allowed permission level. By driving the dynamic safety envelope to adaptively scale and the permission level to progressively decrease through at least one of the perception confidence value, environmental severity estimate, and road user risk value, a smooth transition from full-permission operation to complete exit is achieved, avoiding problems such as sudden function interruption, excessive sensor trust, or unnecessary sensor disabling, while also preventing permission oscillations around thresholds.

[0029] As a first optional embodiment of this embodiment, based on the above embodiment, it further includes: When the currently allowed permission level changes from strict to lenient, the vehicle driving assistance system is controlled after the preset lag conditions and minimum dwell time conditions are met.

[0030] In this embodiment, the preset hysteresis condition refers to the backlash condition set to prevent frequent switching of permission levels near the threshold. Each permission level has an independent trigger threshold and recovery threshold. The recovery threshold is lower than the trigger threshold, and the difference between the two constitutes the hysteresis band. The minimum dwell time condition means that the permission level must maintain the current stricter state for at least a predetermined duration before it can recover to a more lenient state.

[0031] Specifically, permission levels can be set sequentially from lenient to strict. For example, the most lenient permission level is full-authority device, followed by first restricted state, second restricted state, driver return state, and minimum risk maneuver. When the permission level is downgraded from the current state to the corresponding more strict state, the controller immediately executes the state change of the vehicle's driver assistance system to ensure that restrictive measures are taken as soon as the risk increases, avoiding safety risks caused by delays. When the permission level is upgraded from the current state to the corresponding more lenient state, it is first judged by preset hysteresis conditions and risk parameters. The risk parameter must be lower than the preset recovery threshold, and this recovery threshold must be lower than the trigger threshold. Only when the risk parameter is clearly and continuously reduced to a level lower than the trigger threshold is the recovery process allowed to start, thereby avoiding repeated switching of permissions around the threshold. Furthermore, the permission level must remain in the current state for a preset minimum dwell time condition. That is, even if condition one is met, the controller still needs to wait for the minimum dwell time condition before executing permission recovery, thereby confirming that the risk has indeed stabilized and decreased rather than fluctuating instantaneously. After both of the above conditions are met, the permission level is restored in a gradual manner, such as increasing the permission level one at a time, rather than jumping directly from the strict state to the lenient state.

[0032] For example, when a vehicle encounters rainfall while driving, the environmental severity estimate E (range 0~1) changes with the rainfall intensity, and the system manages the permission level based on the E value. Assume the two current permission states are full permission (S0) and first restricted state (S1), with a trigger threshold of 0.7, a recovery threshold of 0.5, and a minimum dwell time of 5 seconds. At time T0, the E value is 0.2, and the event is normal driving in sunny weather; at time T1, it is 0.7, E reaches the trigger threshold, and the system immediately downgrades to S1; at time T2, the E value is 0.85, the event is increased rainfall, and S1 remains unchanged. At time T3, it is 0.45, E decreases below the recovery threshold, and the timer starts; at time T4, the E value is 0.4, meaning the dwell time has reached 5 seconds, and the system gradually recovers to S0.

[0033] For example, Figure 2 This is a schematic diagram illustrating the risk-permission mapping relationship of a vehicle driving assistance system control method according to Embodiment 1 of the present invention. Taking the maximum permissible speed as an example, independent limit thresholds and release thresholds are set. Figure 2 As shown, the horizontal axis represents the fusion risk index R (the R value increases as perceived confidence decreases, environmental severity increases, or road user risk value increases), and the vertical axis represents the maximum permissible speed (reflecting the permission level). The graph includes independent trigger and release thresholds; the trigger threshold is higher than the release threshold, and the difference between the two constitutes the hysteresis band. When the R value rises and reaches the trigger threshold, permission is immediately downgraded (e.g., from full permission to the first restricted state); permission is restored only when the R value falls below the release threshold (e.g., from the first restricted state to the full permission state). When the R value is within the hysteresis band, the permission level remains unchanged, thus preventing oscillations. The solid line in the graph represents the restricted path, and the dashed line represents the recovery path; the difference between the two reflects the hysteresis mechanism.

[0034] As a second optional embodiment of this first embodiment, based on the above embodiment, it further includes: When the dynamic safety envelope is compromised or the currently allowed permission level is lower than the permission required for the current level of automation, a degrade response is triggered. The degrade response includes slowing down, restricting maneuvering, issuing a takeover request to the driver, and / or performing a minimum-risk maneuver.

[0035] In this embodiment, the permission required for the current automation level refers to the minimum permission level required for the currently activated driving assistance function to operate normally. For example, the highway guidance function requires at least the permission level of the first restricted state (S1) to operate normally. If the arbitration result is the second restricted state (S2) or lower, this condition is triggered. When either of the above two triggering conditions is met, the system initiates a downgrade response.

[0036] Specifically, when the vehicle's actual or predicted trajectory approaches or exceeds the boundary of the dynamic safety envelope, which serves as a hard constraint for motion planning, its intrusion may be caused by a sudden decrease in perception confidence leading to a sharp contraction of the envelope, deteriorating environmental conditions causing the envelope to tighten, or a sudden intrusion of a target ahead causing a breach of the safety margin. Alternatively, when the controller determines a permission level lower than the minimum permission level required for the normal operation of the currently activated driver assistance function, the controller triggers a degraded response, such as deceleration, restricting maneuvering, issuing a takeover request to the driver, and / or performing a minimum-risk maneuver. Deceleration involves reducing the vehicle's speed, which can be gradual or a more abrupt reduction. Restricting maneuvering refers to limiting or prohibiting certain driving maneuvers, including prohibiting automatic lane changes, overtaking, and limiting steering range. A takeover request is a prompt to the driver, issued through visual (instrument panel or central control screen), auditory (beep or voice prompt), or tactile (steering wheel or seat vibration) methods, requesting the driver to regain control of the vehicle. Minimum risk maneuver refers to a safe stopping operation automatically performed by the controller when the driver fails to respond to the takeover request within a preset time. This includes controlling the vehicle to decelerate and safely stop in the current lane or changing lanes to the emergency lane and then stopping.

[0037] For example, the controller can select the appropriate degradation response measures based on the severity of the triggering conditions. For instance, when the envelope is slightly intruded (e.g., an impending intrusion is predicted), the controller can first implement deceleration and restrict maneuvering; when the envelope is severely intruded (e.g., the actual trajectory has exceeded the envelope boundary) or the permission level is significantly lower than the required permission, the controller simultaneously or subsequently issues a takeover request to the driver while implementing deceleration and restricting maneuvering; if no driver takeover is detected within a preset time, the lowest-risk maneuver is executed. The application of the aforementioned degradation response is rate-limited, meaning the rate of change of the control command is limited. For example, deceleration commands are not applied in a step manner but gradually decrease the speed at a preset maximum deceleration slope; restricting maneuvering does not cause the vehicle to suddenly yaw but smoothly exits the current maneuver, thereby ensuring driving comfort and vehicle stability during the degradation process.

[0038] Example 2 Figure 3 This is a flowchart of a control method for a vehicle driving assistance system according to Embodiment 2 of the present invention. This embodiment is a further refinement of the above embodiment. Figure 3 As shown, the method includes: S201. Acquire vehicle perception data, sensor health diagnostic data, and environmental data.

[0039] S202. Determine the availability score for each sensor based on the sensor health diagnostic data of each sensor.

[0040] In this embodiment, the availability score can be understood as a quantitative evaluation of the reliability of a single sensor for the current use in sensing tasks, and is a value normalized to the [0,1] interval.

[0041] Specifically, the controller can obtain at least one of the following indicators based on the sensor health diagnosis data: field of view occlusion rate, deviation of effective detection distance from nominal value, signal-to-noise ratio, and data interruption rate. Each indicator is normalized to the [0,1] interval and combined into a usability score for the sensor by weighting or taking the minimum value.

[0042] S203. Merge the usability scores to generate a perceived confidence value.

[0043] Specifically, the sensor can merge the availability scores of multiple sensors in the vehicle to generate a perception confidence value. This merging is performed across each detection task dimension, with different detection tasks (such as longitudinal detection, lateral detection, VRU detection, and free space detection) corresponding to different perception confidence sub-values. Within each detection task, the availability scores of all sensors participating in that task are weighted and summarized; when sensor redundancy exists, the redundant information can improve the perception confidence value for that task; when a single sensor modality required to perform a target detection task is lost, the perception confidence value for that task is reduced.

[0044] S204. Based on the environmental data, generate an estimate of the environmental severity.

[0045] Specifically, the controller can obtain at least one of the following from environmental data: precipitation rate, visibility distance, road friction coefficient, and lighting intensity. Based on the precipitation rate, it can determine the rainfall level (e.g., no rain, light rain, moderate rain, heavy rain), based on the visibility distance, it can determine the visibility level (e.g., good, fair, poor), based on the road friction coefficient, it can determine the road surface adhesion level (e.g., daytime, dusk / dawn, nighttime, glare). Based on at least one of the following: rainfall level, visibility level, road surface adhesion level, and lighting level, it can generate an environmental severity estimate.

[0046] S205. Determine the risk value of road users based on the perception data.

[0047] Specifically, the controller can detect road users around the vehicle from the perception data to determine the situation of these road users. It can also obtain information on densely populated areas where the vehicle is currently located and generate road user risk values ​​based on the number, distance, movement trajectory, classification information, and densely populated areas of vulnerable road users.

[0048] Furthermore, based on the above embodiments, the step of determining the risk value of road users based on perceived data can be refined as follows: Detect road users around the vehicle from the perception data, determine the number of road users, their movement trajectory, distance from the vehicle, and classification information; obtain road user hotspot information at the vehicle's current location; and generate road user risk values ​​based on the number of road users, distance, movement trajectory, classification information, and road user hotspot information.

[0049] In this embodiment, the number of road users refers to the total number of road users detected by the perception system at the current moment within a preset range around the vehicle (e.g., within a certain distance in front, to the side, and behind the vehicle). The motion trajectory refers to the historical movement path and current movement trend of the road users, which may include the road user's direction of movement, speed of movement, and predicted future location. The distance to the vehicle refers to the spatial distance between the road user and the vehicle, which can be an absolute distance or the lateral and longitudinal components relative to the vehicle's motion trajectory. Classification information can be understood as the result of classifying detected road users into different categories, such as classifying road users as pedestrians, cyclists, or road workers, and further distinguishing between children and adults. Road user hotspot area information refers to the geographical context information of the vehicle's current location, indicating whether it is located in an area where road users have a high probability or high density of occurrence. Hotspot area information includes at least one of the following: school district information (near schools, frequent children's activity), work area information (work areas, concentrated population), zebra crossing information (areas where pedestrians cross the road), and bus stop information (frequent passenger boarding and alighting, with a risk of pedestrians suddenly appearing from behind buses). The above information can be obtained through map data (such as POI information in high-precision maps), positioning systems, or V2I communication.

[0050] Specifically, the controller can utilize perception data collected by sensors (such as cameras and LiDAR) to detect vulnerable road users around the vehicle. For example, object detection algorithms can be used to identify pedestrians, cyclists, and other objects from the perception data, and multi-frame data association and tracking algorithms can be used to generate their movement trajectories. The controller can use a deep learning classifier to determine classification information. Based on the location of road users, the controller can determine the absolute distance between the controller and the vehicle, as well as the lateral and longitudinal distance components relative to the vehicle's direction of travel. The controller can obtain road user hotspot information for the vehicle's current location. For example, it can read the POI (Point of Interest) information of the vehicle's current location from a high-precision map or navigation map, or match it with pre-stored hotspot map data through a positioning system, or obtain information on whether the current road is a densely populated area from roadside equipment through V2I communication. The controller can integrate the above-mentioned multiple perception information with the acquired hotspot information to generate a road user risk value.

[0051] For example, the above information can be integrated as follows: the more road users there are, the higher the risk value; the closer the road user is to the vehicle, the higher the risk value; when the movement trajectory indicates that the road user is moving towards the vehicle's path or that a collision is possible, the risk value is higher; children have a higher risk weight than adults, and road workers have a higher risk weight than ordinary pedestrians; when located in a hotspot area, the risk value is based on the perceived information plus a preset hotspot area risk increment or multiplied by a weighting coefficient greater than 1. The above information can be integrated into a single risk value using weighted summation, fuzzy logic, or table lookup. Hotspot area information can proactively increase the risk value even before the perceived data detects a specific road user. For example, when the system determines that the vehicle is near a school zone, even if the perception system has not yet detected a child, the road user risk value can be preset to a certain level, thereby expanding the dynamic safety envelope in advance and restricting the permission level in advance to address the potential risk of a child suddenly appearing on the road. When the perception system actually detects a road user, the risk value is further increased.

[0052] S206. Determine risk parameters based on at least one of the perceived confidence value, the environmental severity estimate, and the road user risk value.

[0053] Specifically, one or more of the aforementioned perceived confidence value, environmental severity estimate, and road user risk value can be used independently or in combination to drive the adjustment of the dynamic safety envelope size and the determination of the permission level.

[0054] S207. Determine the safety margins around the vehicle based on the vehicle's speed, the target relative speed, the road friction coefficient, the perceived confidence value, and the road user risk value.

[0055] In this embodiment, the safety margin refers to the preset safety distance values ​​in all directions (front, rear, and lateral) around the vehicle. The safety margins in each direction collectively define the boundary of the dynamic safety envelope. For example, the front margin refers to the minimum safe distance that should be maintained between the front of the vehicle and an obstacle or boundary in front; the rear margin refers to the minimum safe distance that should be maintained between the rear of the vehicle and an obstacle or boundary behind; and the lateral margin refers to the minimum safe distance that should be maintained between the sides of the vehicle and obstacles or boundaries on the sides. The target relative speed reflects the approach rate of the vehicle to the target in front / behind. The road friction coefficient reflects the road surface adhesion; the lower the friction coefficient (e.g., on a wet or slippery road surface), the longer the braking distance.

[0056] Specifically, the controller can calculate the safety margin around the vehicle based on the vehicle speed, target relative speed, road friction coefficient, perception confidence value, and road user risk value. The above parameters affect the safety margin as follows: the higher the vehicle speed, the longer the braking distance, and the larger the required safety margin; the higher the relative speed, the higher the collision risk, and the larger the required safety margin; the lower the road friction coefficient (e.g., on a slippery road surface), the longer the braking distance, and the larger the required safety margin; the lower the perception confidence value, the higher the perception uncertainty, and the required safety margin should be increased accordingly to compensate for the uncertainty; the higher the road user risk value, the larger the safety margin should be to provide more sufficient response space. In one implementation, the nominal safety margin can be calculated by querying a preset mapping table or through a preset mathematical model based on the above parameters.

[0057] S208. When the perceived confidence value decreases, the environmental severity estimate increases, or the road user risk value increases, the safety margin is expanded based on the magnification factor, and the size of the dynamic safety envelope is determined based on the expanded safety margin.

[0058] In this embodiment, the amplification factor refers to the coefficient used to expand the dynamic safety envelope when the risk increases.

[0059] Specifically, when the perceived confidence value decreases, the estimated environmental severity value increases, or the road user risk value increases, it signifies an increase in risk. The controller can then expand the safety margin in each direction by a magnification factor greater than or equal to 1 (this can be achieved by multiplying the safety margin by the magnification factor), and determine the size of the dynamic safety envelope based on the expanded safety margin. It should be noted that the above three conditions are logically ORed—if any one of the conditions is met (i.e., any risk parameter indicates an increased risk), the safety margin is magnified, resulting in the size of the dynamic safety envelope. For example, when the perceived confidence value decreases but the environmental severity and road user risk values ​​remain unchanged, the safety margin is still expanded by the magnification factor to compensate for the increased perceived uncertainty. The magnification factor can be a uniform global value or a value set independently for each direction. For example, when the road user is located on the right side of the vehicle, the magnification factor for the right lateral margin is greater than that for the left lateral margin, thus asymmetrically expanding the envelope.

[0060] S209. When the perceived confidence value increases, the environmental severity estimate decreases, and the road user risk value decreases, the safety margin is reduced based on the reduction factor, and the size of the dynamic safety envelope is determined based on the reduced safety margin.

[0061] In this embodiment, the reduction factor refers to the coefficient used to reduce the dynamic safety envelope when the risk increases.

[0062] The lower limit of the reduced safety margin is limited by a preset minimum safety value. The minimum safety value is a physical safety lower limit that is pre-calibrated based on the vehicle's braking capacity, system safety requirements, and relevant safety standards. Each direction can have its own minimum safety value set independently. For example, the minimum safety value in front is determined based on the minimum braking distance at the vehicle's current speed, and the minimum safety value in the lateral direction is determined based on the vehicle's width and the minimum lateral safety margin.

[0063] Specifically, when the perceived confidence value increases, the estimated environmental severity value decreases, and the road user risk value decreases, it signifies a reduction in risk. The controller reduces the safety margin in each direction by a reduction factor less than 1 (this can be achieved by multiplying the safety margin by the reduction factor), and determines the size of the dynamic safety envelope based on the reduced safety margin. It's important to note that, unlike the amplification condition, the reduction condition is a logical AND relationship; the safety margin reduction is only triggered when all three risk parameters simultaneously indicate a reduction in risk. As long as any one of the perceived confidence value, estimated environmental severity value, or road user risk value remains in a high-risk state, the safety margin will not be reduced, ensuring that the safety margin is determined by the most unfavorable factor. The reduction factor can be a uniform global value or a value set independently for each direction.

[0064] For example, Figure 4 This is a schematic diagram of the dynamic safety envelope of a control method for a vehicle driving assistance system provided in Embodiment 2 of the present invention, as shown below. Figure 4 As shown, the nominal static area (represented by dashed lines) is a fixed safety area in the prior art. This area is defined by fixed geometric parameters determined during the design phase, such as a rectangular or elliptical area at a fixed distance around the vehicle, and does not adjust with changes in vehicle speed, environmental conditions, or perceived confidence. The size of this static area remains constant regardless of the conditions surrounding the vehicle. The dynamic safety envelope (represented by solid lines) is the dynamic safety space boundary proposed in this invention, jointly defined by the vehicle's front safety margin, rear safety margin, and lateral safety margin. Unlike the nominal static zone, the size of the dynamic safety envelope changes in real time with risk parameters. In the figure, when the perceived confidence value decreases, the estimated environmental severity value increases, and road users are detected around the vehicle, the dynamic safety envelope expands outward, and the safety margins in all directions increase accordingly to compensate for the additional risks brought about by increased perceived uncertainty, environmental deterioration, or the presence of road users. The expanded envelope area is larger than the area of ​​the nominal static zone. The forward safety margin of the dynamic safety envelope takes into account the distance and relative motion state between the vehicle and the vehicle in front. The lateral expansion of the dynamic safety envelope also takes into account the location of road users. When a road user is detected on the left front side of the vehicle, the left lateral safety margin and the forward safety margin can be expanded independently, making the envelope present an asymmetrical shape (expanding to that side) to specifically protect road users.

[0065] S210. Based on risk parameters, determine the currently permitted permission level of the vehicle's driver assistance system.

[0066] Specifically, the controller can determine the currently permitted permission level of the vehicle's driver assistance system from different dimensions based on risk parameters.

[0067] Furthermore, based on the above embodiments, the steps for determining the currently permitted permission level of the vehicle's driver assistance system according to risk parameters can be refined as follows: Based on the perception confidence value, determine the first restriction level corresponding to the sensor health category and different driving direction permission restrictions; based on the environmental severity estimate, determine the second restriction level corresponding to the environmental category and the dynamic safety envelope expansion size, minimum follow time interval, maximum speed limit, and motor type restriction; based on the road user risk value, determine the third restriction level corresponding to the personnel presence category and the dynamic safety envelope expansion direction and speed limit level; based on the first restriction level, second restriction level, and third restriction level, determine the currently allowed permission level.

[0068] In this embodiment, the first restriction level is triggered by the perception confidence value, reflecting the degree to which the sensor health status restricts functional permissions in different driving directions. Different driving direction permission restrictions refer to functional permission restrictions set separately for different driving directions of the vehicle. The second restriction level is triggered by the environmental severity estimate, reflecting the degree to which environmental conditions restrict driver assistance functions. The expansion size of the dynamic safety envelope refers to the extent to which the dynamic safety envelope expands in each direction when environmental conditions deteriorate. The minimum following time interval refers to the minimum allowed time interval (usually in seconds) between the vehicle and the vehicle in front during adaptive cruise control or following. The maximum speed limit refers to the upper limit of the maximum vehicle speed allowed by the system. The maneuver type restriction refers to the restriction on the types of driving maneuvers the vehicle can perform, such as prohibiting automatic lane changing, overtaking, and turning. The third restriction level is triggered by the road user risk value, reflecting the degree to which the presence of vulnerable road users around the vehicle restricts functional permissions. The dynamic safety envelope expansion direction refers to the direction in which the dynamic safety envelope expands asymmetrically in a specific direction when a vulnerable road user is detected. The speed limit level refers to the speed limit gradient set according to the risk level of different road users.

[0069] Specifically, the controller can determine the sensor health restriction level based on the perception confidence value. A higher perception confidence value indicates a better sensor health condition, resulting in a lower first restriction level (fewer restrictions); a lower perception confidence value indicates a worse sensor health condition, resulting in a higher first restriction level (more restrictions). This restriction is direction-specific: front sensor degradation only restricts forward directional permissions (maximum speed and forward safety margin), while side and rear sensor degradation only restricts lateral maneuvering permissions (lane change and steering). For example, if the perception confidence value of the front camera drops below a first threshold due to lens contamination, the first restriction level includes limiting the maximum speed; when the perception confidence value further drops below a second threshold, the first restriction level includes further limiting the maximum speed and restricting the forward safety margin. Similarly, when the perception confidence value of the side and rear radar decreases, the first restriction level includes restricting lane changes to that side.

[0070] Specifically, the controller can determine the environmental restriction level based on the environmental severity estimate. The higher the environmental severity estimate, the higher the second restriction level, and the more stringent the corresponding restrictions. The restrictions corresponding to the second restriction level include the expansion size of the dynamic safety envelope (the extent to which the envelope expands as the environment worsens), the minimum following interval (the extent to which the following distance increases as the environment worsens), the maximum speed limit (the extent to which the vehicle speed decreases as the environment worsens), and the restriction on the type of maneuver (prohibited maneuvers). For example, when the environmental severity estimate indicates light rain, the second restriction level includes moderate envelope expansion and increased time intervals; when the environmental severity estimate indicates heavy rain, fog, or low friction, the second restriction level includes deceleration and disabling automatic lane changing. When road environment information ahead is obtained in advance through V2X communication or cloud data, the second restriction level can be raised in advance before the vehicle arrives at that road segment, realizing pre-adjustment of permissions.

[0071] Specifically, the controller can determine the personnel restriction level based on the road user risk value. The higher the road user risk value, the higher the third restriction level, and the stricter the corresponding restrictions. The restrictions corresponding to the third restriction level include the expansion of the dynamic safety envelope towards the road user (the direction and magnitude of the asymmetric expansion of the envelope) and the speed limit level (the magnitude of the speed reduction). For example, when the road user risk value rises above the first personnel threshold, the third restriction level includes expanding the envelope towards the personnel and limiting the vehicle speed; when the road user risk value rises above the second personnel threshold, the third restriction level includes further limiting the vehicle speed and prohibiting lane changes towards the personnel. The asymmetry of the expansion direction allows the system to specifically protect vulnerable road users while avoiding excessive restrictions on functions in other directions.

[0072] Specifically, the controller can arbitrate the three restriction levels mentioned above to determine the final currently permitted permission level. For each permission dimension (including speed, time interval, maneuver type, and automation level), the most stringent restriction level among the three is selected as the final restriction for that dimension. For example, in the speed dimension, if the first restriction level requires "speed limit 80km / h", the second restriction level requires "speed limit 60km / h", and the third restriction level requires "speed limit 40km / h", then the arbitration result is "speed limit 40km / h". In the maneuver type dimension, if the first restriction level requires "lane change allowed", the second restriction level requires "lane change prohibited", and the third restriction level requires "lane change prohibited", then the arbitration result is "lane change prohibited". Through this arbitration method, it is ensured that all concurrent risk factors are included in the permission decision, and the controller's permissions always meet the most stringent safety requirements. The permission level determined by arbitration includes multiple descending restriction levels (such as full permission state, first restricted state, second restricted state, driver return state, and lowest risk maneuver state), and each restriction level corresponds to a set of functional permission restrictions. The determined currently permitted permission level and the dynamic safety envelope size are used together as inputs for subsequent vehicle control.

[0073] S211. The dynamic safety envelope is used as a hard constraint for the vehicle's motion planning to control the vehicle's trajectory to not exceed the boundary of the dynamic safety envelope.

[0074] In this embodiment, the motion trajectory refers to the vehicle's travel path in space and time, including the sequence of changes in position, speed, acceleration, heading angle, etc. over time.

[0075] Specifically, the controller can use the dynamic safety envelope determined in the previous step as a hard boundary condition for the vehicle's motion planning. When generating candidate trajectories in each control cycle, the motion planner must check whether the trajectory satisfies the envelope constraint, that is, whether the vehicle's position on the trajectory at every moment is within the dynamic safety envelope boundary. If any part of a candidate trajectory exceeds the envelope boundary, the trajectory will be directly discarded and will not proceed to the subsequent trajectory evaluation and selection process.

[0076] S212. Based on the currently allowed permission level, restrict the execution permissions of the vehicle's driver assistance system.

[0077] The execution permissions include at least one of the following: maximum speed limit, minimum follow time interval limit, permitted maneuver type limit, and automation level limit.

[0078] Specifically, the controller can restrict the execution permissions of the driver assistance system based on the currently permitted permission level determined in the previous arbitration step. Execution permissions include at least one of the following: maximum speed limit, minimum follow time interval limit, permitted maneuver type limit, and automation level limit.

[0079] For example, when the permission level is in the first restricted state, the maximum speed limit is 80 km / h; when the permission level is in the second restricted state, the maximum speed limit is 60 km / h. The speed limit can be directly applied to the longitudinal controller, ensuring that the driver assistance system will not issue acceleration commands exceeding this speed limit under any circumstances. When the permission level is in the first restricted state, the minimum following time interval is 2.0 seconds; when the permission level is in the second restricted state, the minimum following time interval is 3.0 seconds. The increased minimum time interval means an increased following distance, providing more time margin for braking response. When the permission level is in the first restricted state, automatic lane changing is prohibited; when the permission level is in the second restricted state, automatic lane changing and overtaking are prohibited; when the permission level is in the driver return state, all maneuvers except for deceleration and stopping are prohibited. Maneuver type restrictions apply to the driver assistance system's maneuver decision module, preventing it from generating prohibited maneuver commands. When the permission level is in the first restricted state, the highway guidance function is disabled, but adaptive cruise control and lane keeping assist can still operate; when the permission level is in the second restricted state, only adaptive cruise control is available; when the permission level is in the driver return state, all automated functions are disabled, and only basic warning and emergency braking functions are retained. The automation level restriction acts on the function arbitration module, which determines which functions can be activated under the current permission level.

[0080] The technical solution of this invention sets the permission level to multiple descending restricted levels, driven by risk parameters to progressively degrade and recover with lag. This avoids the defect in existing technologies where functions are suddenly interrupted at the ODD boundary and control is abruptly returned to the driver. It achieves smooth and predictable functional degradation, significantly improving driving experience and safety. The dynamic safety envelope changes in real time with the risk parameters. When the risk increases, the envelope expands immediately to compensate for the increased uncertainty; when the risk decreases, the envelope contracts under the constraint of a minimum safety value to avoid excessive conservatism. This overcomes the dilemma of the static safety zone being "insufficient safety margin when conditions worsen and overly conservative when conditions are favorable." Sensor health diagnostic data continuously determines the perception confidence value. Degradation of the front sensor restricts forward direction permissions, and degradation of the side and rear sensors restricts lateral maneuver permissions. This allows the system to make fine-grained permission adjustments based on the degree and direction of sensor degradation, overcoming the defect in existing technologies where partial sensor degradation results in either "over-trust or complete disabling." This maximizes system availability while ensuring safety. By determining road user risk values ​​based on road user information detected in the sensing data, the system can proactively tighten safety boundaries and restrict functional permissions in advance based on the number, distance, movement trajectory, classification information, and densely populated areas of vulnerable road users. This overcomes the deficiency in existing technologies where safety boundary tightening lags behind risk escalation. By setting independent trigger and release thresholds, permission restoration is only executed after the risk parameter is below the release threshold and the minimum dwell time is met. The release threshold is lower than the trigger threshold, and the difference between the two constitutes a hysteresis band, effectively preventing permissions from repeatedly oscillating around the threshold and improving the stability and predictability of system behavior.

[0081] Example 3 Figure 5 This is a schematic diagram of the structure of a control device for a vehicle driving assistance system provided in Embodiment 3 of the present invention. Figure 5 As shown, the device includes: The data acquisition module 51 is used to acquire vehicle perception data, sensor health diagnostic data, and environmental data; The parameter determination module 52 is used to determine risk parameters based on the perception data, the sensor health diagnosis data and the environmental data. The risk parameters include at least one of the perception confidence value, the environmental severity estimate and the road user risk value. The level determination module 53 is used to determine the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system based on the risk parameters. The permission level includes multiple restricted levels, and each restricted level corresponds to a set of functional permission restrictions. The system control module 54 is used to control the vehicle driving assistance system according to the size of the dynamic safety envelope and the currently allowed permission level.

[0082] Furthermore, the parameter determination module 52 includes: The first determining unit is used to determine the availability score of each sensor based on the sensor health diagnostic data of each sensor; The second determining unit is used to merge the availability scores to generate a perceived confidence value; The third determining unit is used to generate an environmental severity estimate based on the environmental data; The fourth determining unit is used to determine the risk value of the road user based on the perceived data; The fifth determining unit is used to determine risk parameters based on at least one of the perceived confidence value, the environmental severity estimate, and the road user risk value.

[0083] Specifically, the fourth determining unit is used for: Detect road users around the vehicle from the perceived data, and determine the number of road users, their movement trajectories, their distance from the vehicle, and their classification information; Obtain the road user hotspot area information of the current location of the vehicle; Based on the number of road users, distance, movement trajectory, classification information, and hotspot area information of road users, a road user risk value is generated.

[0084] Furthermore, the level determination module 53 includes: The sixth determining unit is used to determine the safety margin around the vehicle based on the vehicle speed, the target relative speed, the road friction coefficient, the perception confidence value, and the road user risk value. The seventh determining unit is used to expand the safety margin based on an amplification factor when the perceived confidence value decreases, the environmental severity estimate increases, or the road user risk value increases, and to determine the size of the dynamic safety envelope based on the expanded safety margin. The eighth determining unit is used to reduce the safety margin based on a reduction factor when the perceived confidence value increases, the environmental severity estimate decreases, and the road user risk value decreases, and to determine the size of the dynamic safety envelope based on the reduced safety margin, wherein the lower limit of the reduced safety margin is limited by a preset minimum safety value. The ninth determining unit is used to determine the currently permitted permission level of the vehicle driving assistance system based on the risk parameters.

[0085] Specifically, the ninth determining unit is used for: Based on the perceived confidence value, determine the first restriction level corresponding to the sensor health category and the permission restrictions for different driving directions; Based on the environmental severity estimate, determine the second restriction level corresponding to the environmental category and the extended size, minimum follow time interval, maximum speed limit, and maneuver type limit of the dynamic safety envelope; Based on the road user risk value, determine the third restriction level corresponding to the personnel presence category and the dynamic safety envelope expansion direction and speed restriction level; The currently allowed permission level is determined based on the first restriction level, the second restriction level, and the third restriction level.

[0086] Furthermore, the system control module 54 is specifically used for: The dynamic safety envelope is used as a hard constraint for the vehicle's motion planning, controlling the vehicle's trajectory to not exceed the boundary of the dynamic safety envelope; Based on the currently permitted permission level, the execution permissions of the vehicle driving assistance system are restricted, including at least one of the following: maximum speed limit, minimum follow time interval limit, permitted maneuver type limit, and automation level limit.

[0087] Optionally, the device further includes: The delay control module is used to control the vehicle driving assistance system after satisfying preset lag conditions and minimum dwell time conditions when the currently allowed permission level changes from strict to lenient.

[0088] Optionally, the device further includes: The degradation control module is used to trigger a degradation response when the dynamic security envelope is compromised or the currently allowed permission level is lower than the permission required for the current automation level. The degradation response includes deceleration, limiting maneuvering, issuing a takeover request to the driver, and / or performing a minimum-risk maneuver.

[0089] The control device for the vehicle driving assistance system provided in the embodiments of the present invention can execute the control method for the vehicle driving assistance system provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0090] Example 4 Figure 6 This is a structural schematic diagram of a vehicle provided in Embodiment 4 of the present invention, as shown below. Figure 6 As shown, the vehicle includes a controller 61, a memory 62, an input device 63, and an output device 64; the number of controllers 61 in the vehicle can be one or more. Figure 6Taking a controller 61 as an example; the controller 61, memory 62, input device 63, output device 64, and vehicle-mounted DVR camera 65 in the vehicle can be connected via bus or other means. Figure 6 Taking the example of a connection between China and Israel via a bus.

[0091] The memory 62, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the control method of the vehicle driving assistance system in this embodiment of the invention (e.g., the data acquisition module 51, parameter determination module 52, level determination module 53, and system control module 54 in the control device of the vehicle driving assistance system). The controller 61 executes various functional applications and data processing of the vehicle by running the software programs, instructions, and modules stored in the memory 62, thereby realizing the control method of the vehicle driving assistance system described above.

[0092] The memory 62 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a given function; the data storage area may store data created based on terminal usage. Furthermore, the memory 62 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory, or other non-volatile solid-state storage device. In some instances, the memory 62 may further include memory remotely configured relative to the controller 61, which can be connected to the vehicle via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0093] Input device 63 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the cloud platform. Output device 64 may include display devices such as a display screen.

[0094] Example 5 Embodiment 5 of the present invention also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform a control method for a vehicle driving assistance system, including: Acquire vehicle perception data, sensor health diagnostic data, and environmental data; Based on the perceived data, the sensor health diagnostic data, and the environmental data, risk parameters are determined, including at least one of the perceived confidence value, the environmental severity estimate, and the road user risk value. Based on the risk parameters, the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system are determined. The permission level includes multiple restricted levels, and each restricted level corresponds to a set of functional permission restrictions. The vehicle driving assistance system is controlled based on the size of the dynamic safety envelope and the currently permitted permission level.

[0095] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0096] It is worth noting that in the embodiments of the control device of the above-mentioned vehicle driving assistance system, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.

[0097] In one embodiment, the present invention further includes a computer program product, which includes a computer program that, when executed by a processor, implements the transaction rate limiting method of any embodiment of the present invention.

[0098] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0099] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A control method for a vehicle driving assistance system, characterized in that, include: Acquire vehicle perception data, sensor health diagnostic data, and environmental data; Based on the perceived data, the sensor health diagnostic data, and the environmental data, risk parameters are determined, including at least one of the perceived confidence value, the environmental severity estimate, and the road user risk value. Based on the risk parameters, the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system are determined. The permission level includes multiple restricted levels, and each restricted level corresponds to a set of functional permission restrictions. The vehicle driving assistance system is controlled based on the size of the dynamic safety envelope and the currently permitted permission level.

2. The method according to claim 1, characterized in that, The step of determining risk parameters based on the perceived data, the sensor health diagnostic data, and the environmental data includes: Based on the sensor health diagnostic data of each sensor, determine the availability score of each sensor; The usability scores are combined to generate a perceived confidence value; Based on the environmental data, an environmental severity estimate is generated; Based on the perceived data, the risk value of road users is determined; Risk parameters are determined based on at least one of the perceived confidence value, the environmental severity estimate, and the road user risk value.

3. The method according to claim 2, characterized in that, The step of determining the road user risk value based on the perceived data includes: Detect road users around the vehicle from the perceived data, and determine the number of road users, their movement trajectories, their distance from the vehicle, and their classification information; Obtain the road user hotspot area information of the current location of the vehicle; Based on the number of road users, distance, movement trajectory, classification information, and hotspot area information of road users, a road user risk value is generated.

4. The method according to claim 1, characterized in that, The step of determining the size of the dynamic safety envelope and the currently permitted permission level of the vehicle driving assistance system based on the risk parameters includes: Based on the vehicle speed, the target relative speed, the road friction coefficient, the perception confidence value, and the road user risk value, the safety margin around the vehicle is determined. When the perceived confidence value decreases, the environmental severity estimate increases, or the road user risk value increases, the safety margin is expanded based on the magnification factor, and the size of the dynamic safety envelope is determined based on the expanded safety margin. When the perceived confidence value increases, the environmental severity estimate decreases, and the road user risk value decreases, the safety margin is reduced based on the reduction factor, and the size of the dynamic safety envelope is determined based on the reduced safety margin, wherein the lower limit of the reduced safety margin is limited by a preset minimum safety value. Based on the risk parameters, determine the currently permitted permission level of the vehicle's driver assistance system.

5. The method according to claim 4, characterized in that, The step of determining the currently permitted permission level of the vehicle driving assistance system based on the risk parameters includes: Based on the perceived confidence value, determine the first restriction level corresponding to the sensor health category and the permission restrictions for different driving directions; Based on the environmental severity estimate, determine the second restriction level corresponding to the environmental category and the extended size, minimum follow time interval, maximum speed limit, and maneuver type limit of the dynamic safety envelope; Based on the road user risk value, determine the third restriction level corresponding to the personnel presence category and the dynamic safety envelope expansion direction and speed restriction level; The currently allowed permission level is determined based on the first restriction level, the second restriction level, and the third restriction level.

6. The method according to claim 1, characterized in that, The step of controlling the vehicle driving assistance system based on the size of the dynamic safety envelope and the currently permitted permission level includes: The dynamic safety envelope is used as a hard constraint for the vehicle's motion planning, controlling the vehicle's trajectory to not exceed the boundary of the dynamic safety envelope; Based on the currently permitted permission level, the execution permissions of the vehicle driving assistance system are restricted, including at least one of the following: maximum speed limit, minimum follow time interval limit, permitted maneuver type limit, and automation level limit.

7. The method according to claim 1, characterized in that, Also includes: When the currently allowed permission level changes from strict to lenient, the vehicle driving assistance system is controlled after the preset lag condition and minimum dwell time condition are met.

8. The method according to claim 1, characterized in that, Also includes: When the dynamic safety envelope is compromised or the currently allowed permission level is lower than the permission required for the current automation level, a degradation response is triggered, which includes deceleration, limiting maneuverability, issuing a takeover request to the driver, and / or performing a minimum-risk maneuver.

9. A control device for a vehicle driving assistance system, characterized in that, include: The data acquisition module is used to acquire vehicle perception data, sensor health diagnostic data, and environmental data; The parameter determination module is used to determine risk parameters based on the perception data, the sensor health diagnosis data, and the environmental data. The risk parameters include at least one of the perception confidence value, the environmental severity estimate, and the road user risk value. The level determination module is used to determine the size of the dynamic safety envelope and the currently allowed permission level of the vehicle driving assistance system based on the risk parameters. The permission level includes multiple restricted levels, and each restricted level corresponds to a set of functional permission restrictions. The system control module is used to control the vehicle driving assistance system according to the size of the dynamic safety envelope and the currently allowed permission level.

10. A vehicle, characterized in that, The vehicles include: At least one controller; and A memory communicatively connected to the at least one controller; wherein, The memory stores a computer program that can be executed by the at least one controller, the computer program being executed by the at least one controller to enable the at least one controller to perform the control method of the vehicle driving assistance system according to any one of claims 1-8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause the controller to implement the control method of the vehicle driving assistance system according to any one of claims 1-8 when executed.