Intelligent driving method, intelligent driving domain controller, and sensor

By switching vehicle control instructions when SoC and MCU fail in the intelligent driving domain controller, redundant backup of intelligent driving functions is realized, solving the problem of high complexity of redundant backup in the existing technology, reducing development costs and improving control efficiency and accuracy.

WO2025148324A1PCT designated stage expired Publication Date: 2025-07-17YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Patent Information

Application Number
PCT/CN2024/113441
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-09
Filing Date
2024-08-20
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

In the prior art, the redundant backup solution of the intelligent driving domain controller is complex, resulting in high development costs and prone to abnormal situations such as data surface fracture and data loss.

Method used

In the intelligent driving domain controller, the SoC receives sensor data and outputs vehicle control instructions through the target sensor when the MCU fails, or the MCU receives data and outputs vehicle control instructions when the SoC fails, achieving redundant backup and avoiding the deployment of two intelligent driving domain controllers.

Benefits of technology

Reduces the complexity of redundant backup solutions, reduces development costs, and improves the efficiency and accuracy of vehicle control, ensuring driving safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024113441_17072025_PF_FP_ABST
    Figure CN2024113441_17072025_PF_FP_ABST
Patent Text Reader

Abstract

An intelligent driving method, an intelligent driving domain controller, and a sensor, relating to the technical field of intelligent driving. The complexity of a redundant backup scheme for realizing an intelligent driving function can be reduced, the problem of complexity caused by deployment of two intelligent driving domain controllers is avoided, and development costs are reduced. The method comprises: an SoC in an intelligent driving domain controller receives first sensing data from M sensors, and when an MCU in the intelligent driving domain controller fails, the SoC sends first information to a target sensor on the basis of the first sensing data, such that the target sensor outputs a first vehicle control instruction to control a vehicle, wherein the target sensor is one of the M sensors.
Need to check novelty before this filing date? Find Prior Art

Description

Intelligent driving method, intelligent driving domain controller and sensor

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 9, 2024, with application number 202410033960.1 and application name “Intelligent Driving Method, Intelligent Driving Domain Controller and Sensor”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of intelligent driving technology, and in particular to intelligent driving methods, intelligent driving domain controllers, and sensors. Background Art

[0003] Automotive safety integrity levels (ASIL) are derived from the international standard ISO 26262 (Road Vehicles – Functional Safety). This standard specifies functional safety requirements for automotive electrical and electronic systems (such as motors, controllers, and software). Currently, ASILs are categorized into five levels: quality management (QM), A, B, C, and D. The functional safety requirements for each level increase in descending order.

[0004] With the development of intelligent driving technology, in order to meet the requirements of functional safety, the need for redundant backup of in-vehicle components with ASIL B and above has been proposed. Taking the intelligent driving domain controller in the vehicle as an example, the current method is to simultaneously deploy two intelligent driving domain controllers to achieve redundant backup of intelligent driving functions. However, this solution is complex to implement. For example, time synchronization solutions and data plane switching solutions must be deployed on both intelligent driving domain controllers, and various abnormal situations such as data plane interruption and data loss often occur. In addition, it is difficult to deploy and run intelligent driving services on the intelligent driving domain controllers, which is difficult to develop and has high costs.

[0005] Summary of the Invention

[0006] The present application provides an intelligent driving method, an intelligent driving domain controller, and a sensor, which can reduce the complexity of the redundant backup solution for implementing intelligent driving functions, avoid the complex problems caused by deploying two intelligent driving domain controllers, and reduce development costs.

[0007] To achieve the above objectives, this application adopts the following technical solutions:

[0008] In a first aspect, an intelligent driving method is provided, which is applied to an intelligent driving domain controller of a vehicle, the intelligent driving domain controller including a system-on-chip (SoC) and a microcontroller unit (MCU). The method includes: the SoC receiving first perception data from M sensors, where M is greater than or equal to 2; in the event of failure of the MCU, the SoC sending first information to a target sensor based on the first perception data, so that the target sensor outputs a first vehicle control instruction to control the vehicle, and the target sensor is one of the M sensors.

[0009] Based on this technical solution, after the SoC receives sensor data, if the MCU fails, it can send the first information derived from the sensory calculation to the target sensor, which then outputs vehicle control commands to achieve vehicle control, such as autonomous driving. This not only provides redundant backup for intelligent driving functions, but also eliminates the need to deploy two intelligent driving domain controllers, avoiding the complexities associated with deploying two intelligent driving domain controllers and reducing development costs.

[0010] In one possible design, the method further includes: if the MCU is not failed, the SoC sends the first information to the MCU based on the first perception data, so that the MCU outputs a second vehicle control command to control the vehicle. Based on this design, after the SoC receives the perception data from the sensor, if the MCU is not failed, it can send the first information calculated based on the perception data to the MCU, which then outputs the vehicle control command to achieve vehicle control, such as autonomous driving. This provides redundant backup for intelligent driving functions, avoids the complexities associated with deploying two intelligent driving domain controllers, and reduces development costs. Furthermore, the vehicle control command is preferentially outputted through the MCU rather than the target sensor. Because both the SoC and the MCU are located in the intelligent driving domain controller, the communication link is shorter than the communication link used to transmit the first information to the target sensor. Furthermore, the MCU has greater computing power than the target sensor. This reduces signal transmission time, increases computing speed, and thereby improves vehicle control efficiency and accuracy.

[0011] In one possible design, the method further includes: the MCU receives second perception data from N sensors, where N is less than M; and in the event that the SoC fails, the MCU outputs a third vehicle control instruction based on the second perception data to control the vehicle. Based on this design, after the MCU obtains the perception data from the sensor, if the SoC fails, it calculates the vehicle control instruction based on the perception data to achieve control of the vehicle. This can achieve redundant backup of the intelligent driving function, avoid the complex problems caused by deploying two intelligent driving domain controllers, and reduce development costs. In addition, the computing power of the MCU is better than that of the target sensor, so that in the event of a SoC failure, the vehicle can be controlled by the MCU, which can improve the control efficiency and accuracy of the vehicle.

[0012] In one possible design, the first information is a vehicle control command, or the first information is a perception result calculated based on the first perception data. Based on this design, the SoC directly calculates the vehicle control command, which can improve the calculation efficiency of the vehicle control command. The SoC only calculates the perception result, and the target sensor or MCU further calculates the vehicle control command. Since the MCU and target sensor are generally rated ASILD, and the SoC is generally rated QM or ASILB, this can improve the safety and reliability of the vehicle control command.

[0013] In one possible design, the method further includes: in a case where the MCU fails for more than a first preset time, the SoC sends a second message to the target sensor to control the vehicle to stop or stop controlling the vehicle. Based on this design, in the case of MCU failure, the SoC controls the vehicle for the first preset time, that is, it only controls the vehicle for a period of time. Since the MCU fails, that is, the vehicle malfunctions, the safety of the vehicle will be reduced. In this way, controlling the vehicle to continue automatic driving for only a period of time can not only ensure driving safety, but also improve the driver experience and give the driver more reaction time to take over the vehicle.

[0014] In one possible design, the method further includes: in the event that the SoC fails for more than a second preset time, the MCU controls the vehicle to stop or stops controlling the vehicle. Based on this design, in the event of a SoC failure, the MCU controls the vehicle for the second preset time, that is, it only controls the vehicle for a period of time. Due to the failure of the SoC, that is, the vehicle has a malfunction, the safety of the vehicle will be reduced. In this way, controlling the vehicle to continue automatic driving for only a period of time can not only ensure driving safety, but also improve the driver experience and give the driver more reaction time to take over the vehicle.

[0015] In one possible design, the method further includes: the SoC determining whether the MCU has failed by monitoring the heartbeat of the MCU; and / or the MCU determining whether the SoC has failed by monitoring the heartbeat of the SoC. Based on this design, the SoC can determine whether the MCU has failed by monitoring the heartbeat of the MCU, and further determine whether to send the first information to the target sensor to control the vehicle through the target sensor. The MCU can determine whether the SoC has failed by monitoring the heartbeat of the SoC, and further determine whether to control the vehicle based on the received sensing data to control the vehicle.

[0016] In one possible design, the method further includes: the SoC receiving indication information from the target sensor, the indication information being used to indicate whether the MCU has failed; and / or the MCU receiving indication information from the target sensor, the indication information being used to indicate whether the SoC has failed. Based on this design, the SoC and MCU can both determine whether the other has failed based on the indication information from the target sensor. In other words, the target sensor monitors whether the SoC and MCU have failed and then notifies the SoC and MCU, which can save the power consumption of the SoC and MCU monitoring each other's heartbeats.

[0017] In one possible design, the M sensors include at least a forward radar and an intelligent forward-looking camera IFC, and the target sensor is the IFC. Based on this design, the target sensor is the IFC. Since the IFC not only contains traditional camera modules and other equipment, but also contains a small computing unit with certain computing capabilities, it can realize functions such as obstacle detection. In this way, after the IFC receives the perception results from the SoC, it can calculate the vehicle control instructions based on its own computing power, and thus realize the control of the vehicle. The forward radar serves as a forward obstacle perception module, has the ability to perceive short and medium distances in intelligent driving, and can provide obstacle identification information. And it is a different type of sensor from the IFC, which can make the perception data richer and the vehicle control instructions more accurate.

[0018] In a second aspect, an intelligent driving method is provided, which is applied to a target sensor on a vehicle, and the vehicle also includes an intelligent driving domain controller. The method includes: when the SoC and MCU of the intelligent driving domain controller fail, receiving perception data from a first sensor; and outputting vehicle control instructions based on the perception data of the target sensor and the perception data of the first sensor to control the vehicle.

[0019] Based on this technical solution, if both the SoC and MCU fail, the target sensor receives the perception data from connected sensors and uses this data to control the vehicle, such as intelligent driving. This provides redundant backup for intelligent driving functions. Furthermore, the deployment of two intelligent driving domain controllers is eliminated, avoiding the complexities inherent in deploying two domain controllers and reducing development costs.

[0020] In one possible design, the method further includes: receiving first information from the SoC in the event that only the MCU fails; and outputting another vehicle control instruction based on the first information to control the vehicle. Based on this design, if only the MCU fails, the first information from the SoC can be received, and based on the first information, a vehicle control instruction can be output to achieve control of the vehicle, such as achieving autonomous driving of the vehicle. In this way, if the SoC is not failed, the SoC will be given priority to perform various complex calculations related to intelligent driving. Since the SoC has higher computing power than the target sensor, this can improve the vehicle's control accuracy and efficiency and save the perception data of the target sensor.

[0021] In one possible design, after outputting a vehicle control command based on the target sensor's perception data and the first sensor's perception data to control the vehicle, the method further includes: transmitting the vehicle control command to an actuator corresponding to the vehicle control command via a controller area network (CAN) bus. Based on this design, the target sensor can also establish a connection to the CAN bus, allowing the target sensor to transmit its own vehicle control command or a vehicle control command from the SoC to the vehicle's actuator to achieve vehicle control.

[0022] In one possible design, the first information is the other vehicle control instruction, or the first information is a perception result calculated based on perception data of M sensors, M is greater than or equal to 2, and the M sensors include the target sensor and the first sensor.

[0023] In one possible design, before outputting a vehicle control command based on the target sensor's perception data and the first sensor's perception data to control the vehicle, the method further includes: obtaining a compensation signal via the CAN bus, wherein the compensation signal is used to compensate for errors in the target sensor's perception data caused by the vehicle's motion. Based on this design, if both the MCU and the SoC fail, the target sensor can obtain a compensation signal via the CAN bus to compensate for errors in the perception data, making the perception data more accurate, thereby obtaining more precise vehicle control commands and improving vehicle control accuracy.

[0024] In one possible design, the method further includes: receiving a first synchronization signal and a first compensation signal from the SoC, and receiving a second synchronization signal and a second compensation signal from the MCU when both the SoC and the MCU are still functioning; performing time synchronization based on the first synchronization signal, and compensating for errors in the target sensor's perception data caused by the vehicle's motion based on the first compensation signal; and receiving a second synchronization signal and a second compensation signal from the MCU when the SoC fails; performing time synchronization based on the second synchronization signal, and compensating for errors in the target sensor's perception data caused by the vehicle's motion based on the second compensation signal. Based on this design, when both the SoC and the MCU are still functioning, after the target sensor simultaneously receives the synchronization signals and compensation signals from both, the SoC signal is used as the basis for time synchronization and error compensation. When the SoC fails, performing time synchronization and error compensation based on the MCU signal can improve the control accuracy of the target sensor when controlling the vehicle.

[0025] In one possible design, the method further includes: when both the SoC and the MCU fail for more than a preset time, stopping controlling the vehicle or controlling the vehicle to stop based on the perception data of the target sensor and the perception data of the first sensor. Based on this design, when both the MCU and the SoC fail, the target sensor controls the vehicle for a preset time, that is, the vehicle is only controlled for a period of time. Since both the MCU and the SoC fail, that is, the vehicle malfunctions, the safety of the vehicle will be reduced. In this way, controlling the vehicle to continue automatic driving for only a period of time can not only ensure driving safety, but also improve the driver experience and give the driver more reaction time to take over the vehicle.

[0026] In one possible design, the target sensor is an IFC, and the first sensor is a forward-facing radar. Based on this design, the forward-facing radar is the target sensor, meaning that when the IFC controls the vehicle, a forward-facing sensor is selected for obstacle sensing. This improves vehicle control safety and accuracy compared to sensors in other directions. Furthermore, the forward-facing radar and IFC are different types of sensors, which enriches perception data and improves vehicle control safety and accuracy.

[0027] In a third aspect, an intelligent driving domain controller is provided, comprising a system-on-chip (SoC) and an MCU. The SoC is configured to receive first perception data from M sensors, where M is greater than or equal to 2; and, in the event of a failure of the MCU, send first information to a target sensor based on the first perception data, causing the target sensor to output a first vehicle control command to control the vehicle. The target sensor is one of the M sensors.

[0028] In one possible design, the SoC is also used to: when the MCU is not failed, send the first information to the MCU based on the first perception data, so that the MCU outputs a second vehicle control instruction to control the vehicle.

[0029] In one possible design, the MCU is used to: receive second perception data from N sensors, where N is less than M; and in the event that the SoC fails, output a third vehicle control instruction based on the second perception data to control the vehicle.

[0030] In one possible design, the first information is a vehicle control instruction, or the first information is a perception result calculated based on the first perception data.

[0031] In one possible design, the SoC is further used to: send second information to the target sensor to control the vehicle to stop or stop controlling the vehicle when the MCU fails for more than a first preset time period.

[0032] In one possible design, the SoC is further used to: control the vehicle to stop or stop controlling the vehicle when the SoC fails for more than a second preset time period.

[0033] In one possible design, the SoC is further used to: determine whether the MCU has failed by monitoring the heartbeat of the MCU; and / or, the SoC is further used to: determine whether the SoC has failed by monitoring the heartbeat of the SoC.

[0034] In one possible design, the SoC is also used to: receive indication information from the target sensor, wherein the indication information is used to indicate whether the MCU has failed; and / or, the MCU is also used to: receive indication information from the target sensor, wherein the indication information is used to indicate whether the SoC has failed.

[0035] In one possible design, the M sensors include at least a forward radar and an intelligent forward-looking camera IFC, and the target sensor is the IFC.

[0036] In a fourth aspect, a sensor is provided, which includes a communication unit (or communication module) and a processing unit (or processing module); the communication unit is used to receive perception data from a first sensor when the SoC and MCU of the intelligent driving domain controller fail; the processing unit is used to output vehicle control instructions based on the perception data of the target sensor and the perception data of the first sensor to control the vehicle.

[0037] In one possible design, the communication unit is further used to receive first information from the SoC when only the MCU fails; the processing unit is further used to output another vehicle control instruction to control the vehicle based on the first information.

[0038] In one possible design, the communication unit is further used to send the vehicle control instruction to the actuator corresponding to the vehicle control instruction through the controller area network (CAN) bus.

[0039] In one possible design, the first information is the other vehicle control instruction, or the first information is a perception result calculated based on perception data of M sensors, M is greater than or equal to 2, and the M sensors include the target sensor and the first sensor.

[0040] In one possible design, the communication unit is further used to obtain a compensation signal through a CAN bus, where the compensation signal is used to compensate for errors in the perception data of the target sensor caused by the movement of the vehicle.

[0041] In one possible design, the communication unit is further used to receive a first synchronization signal and a first compensation signal from the SoC, and to receive a second synchronization signal and a second compensation signal from the MCU when both the SoC and the MCU are intact; the processing unit is further used to perform time synchronization based on the first synchronization signal, and to compensate for errors in the perception data of the target sensor caused by the movement of the vehicle based on the first compensation signal; the communication unit is further used to receive the second synchronization signal and the second compensation signal from the MCU when the SoC fails; the processing unit is further used to perform time synchronization based on the second synchronization signal, and to compensate for errors in the perception data of the target sensor caused by the movement of the vehicle based on the second compensation signal.

[0042] In one possible design, the processing unit is also used to stop controlling the vehicle or control the vehicle to stop based on the perception data of the target sensor and the perception data of the first sensor when both the SoC and the MCU fail for more than a preset time.

[0043] In one possible design, the target sensor is an IFC, and the first sensor is a forward radar.

[0044] In a fifth aspect, a sensor is provided, comprising a processor, wherein the processor is configured to execute a computer program or instruction so that the method described in the second aspect and any one of the designs thereof is executed.

[0045] In one possible design, the sensor may further include a memory for storing computer programs or instructions. Optionally, the memory may be coupled to the processor or may be independent of the processor.

[0046] In one possible design, the sensor may further include a communication interface that can be used to communicate with other devices (such as the intelligent driving domain controller, the first sensor, etc.). For example, the communication interface can be a transceiver, an input / output interface, an interface circuit, an output circuit, an input circuit, a pin, or related circuits.

[0047] In a sixth aspect, an intelligent driving system is provided, comprising an intelligent driving domain controller as described in the third aspect and any one of the designs thereof, and a sensor as described in any one of the designs of the fourth aspect or the fifth aspect.

[0048] In the seventh aspect, a vehicle is provided, comprising the intelligent driving domain controller as described in the third aspect and any one of the designs thereof and the sensor as described in any one of the designs of the fourth aspect or the fifth aspect.

[0049] In an eighth aspect, a computer-readable storage medium is provided. The computer-readable storage medium includes a computer program. When the computer program is executed on an intelligent driving domain controller, the intelligent driving domain controller executes the method described in the first aspect and any one of the designs therein. When the computer program is executed on a sensor, the sensor executes the method described in the second aspect and any one of the designs therein.

[0050] In the ninth aspect, a computer program product is provided, which includes: a computer program or instructions, which, when the computer program or instructions are run on a computer, enables the computer to execute the method described in the first aspect or the second aspect and any design thereof.

[0051] In the tenth aspect, a chip system is provided, comprising at least one processor and at least one interface circuit, wherein the at least one interface circuit is used to perform transceiver functions and send instructions to the at least one processor. When the at least one processor executes the instructions, the at least one processor executes the method described in any one of the designs in the first or second aspect above.

[0052] It should be noted that the technical effects brought about by any design in the above-mentioned third to tenth aspects can refer to the technical effects brought about by the corresponding design in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] FIG1 is a schematic structural diagram of a vehicle provided in an embodiment of the present application;

[0054] FIG2 is a schematic diagram of a deployment architecture of an intelligent driving domain controller provided in an embodiment of the present application;

[0055] FIG3 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;

[0056] FIG4 is a schematic diagram of the structure of a sensor provided in an embodiment of the present application;

[0057] FIG5 is a schematic diagram of a flow chart of an intelligent driving method provided in an embodiment of the present application;

[0058] FIG6 is a schematic diagram of a flow chart of another intelligent driving method provided in an embodiment of the present application;

[0059] FIG7 is a schematic diagram of a flow chart of another intelligent driving method provided in an embodiment of the present application;

[0060] FIG8 is a schematic structural diagram of another sensor provided in an embodiment of the present application. DETAILED DESCRIPTION

[0061] In the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in this application is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural.

[0062] To facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the words "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that the words "first" and "second" do not limit the quantity or execution order, and the words "first" and "second" do not necessarily mean different.

[0063] Currently, the entire vehicle can be divided into several areas (also called "functional domains") according to the functions of each part of the vehicle. For example, in some implementations, the entire vehicle can be divided into the intelligent driving domain, cockpit domain, chassis domain, power domain, body domain, etc. It is understandable that for different manufacturers, the domains divided according to their own concepts may be different. In addition, multiple domains can also be integrated across domains to obtain a fusion domain. The controllers of each domain can use stronger processing power to relatively centrally control the corresponding domain, realizing the integration of on-board computing required for multiple functions. Among them, the intelligent driving domain controller (such as the mobile data center (MDC) provided by Huawei) is the "brain" that realizes intelligent driving perception, map and sensor fusion positioning, path planning, decision control and other functions.

[0064] As shown in Figure 1, the intelligent driving domain controller 101 can be installed on the vehicle 100 and is responsible for autonomous driving-related perception, decision-making, and control functions. In some scenarios, the intelligent driving domain controller 101 can support multiple interface protocols to enable communication with other devices on the vehicle 100. For example, it can communicate with various sensors installed on the vehicle 100 (e.g., camera 102, lidar 103, millimeter-wave radar 104, etc.), obtain information perceived by these sensors, fuse this information, make driving decisions / plans based on the fused information, and issue operation commands (or vehicle control instructions, etc.) based on the driving decisions / plans to the vehicle controller unit (VCU) 105. The VCU 105 controls the actuators of the vehicle 100 to perform corresponding actions, such as acceleration / deceleration, lane change, steering, braking, or warnings. Alternatively, it can directly issue operation commands to the actuators of the vehicle 100 to control them to perform corresponding actions.

[0065] In some implementations, the intelligent driving domain controller includes a computing unit and a control unit, wherein the computing unit is implemented in the form of a system-on-chip (SoC) and the control unit is implemented in the form of a microcontroller unit (MCU). The SoC is used to implement operations such as logic processing, image processing, artificial intelligence (AI) processing, and storage processing, which are respectively implemented through a central processing unit (CPU), an image processor, an AI processor, and memory. The SoC is generally rated QM or ASIL B, while the MCU is generally rated ASIL D.

[0066] Currently, in order to meet the functional safety requirements of smart driving regulations, a requirement for redundant backup of smart driving domain controllers is proposed, such as deploying two smart driving domain controllers at the same time to achieve redundant backup of smart driving functions. For example, FIG2 shows an exemplary deployment architecture diagram of a smart driving domain controller. As shown in FIG2, a smart driving domain controller 1 and a smart driving domain controller 2 are deployed in a vehicle. The smart driving domain controller 1 and the smart driving domain controller 2 are connected to sensors (such as but not limited to camera 1, camera 2, lidar, millimeter wave radar, etc.) and actuators (such as chassis) in the vehicle. When the smart driving domain controller 1 is not failed (or called a fault, or called a functional abnormality, etc.), the smart driving domain controller 1 can receive perception data from the sensor and send vehicle control commands to the actuator based on the perception data. Accordingly, after receiving the vehicle control command from the smart driving domain controller 1, the actuator executes the vehicle control command, which can realize vehicle acceleration, deceleration, lane change, steering, braking, or warning, etc.

[0067] If intelligent driving domain controller 1 fails, intelligent driving domain controller 2 can receive sensor data and, based on this data, send vehicle control commands to the actuators. Correspondingly, upon receiving the vehicle control commands from intelligent driving domain controller 2, the actuators can also execute these commands to accelerate, decelerate, change lanes, steer, brake, or issue warnings.

[0068] The above redundant backup solution is complex to implement. For example, time synchronization solutions and data plane switching solutions need to be deployed on both intelligent driving domain controllers. Various abnormal situations such as data plane disconnection and data loss often occur. In addition, the intelligent driving services deployed at the upper layer need to be switched on different intelligent driving domain controllers, which makes development difficult and costly.

[0069] In some scenarios, different clock crystals and data transmission paths exist for various sensors within a vehicle. Furthermore, there is a time delay between data acquisition, processing, and sending to the intelligent driving domain controller, and the duration of this delay can be unstable. Therefore, to improve the performance of sensor fusion, decision-making, and integrated positioning in autonomous driving, the intelligent driving domain controller and various sensors must be time synchronized.

[0070] Based on this, an embodiment of the present application provides an intelligent driving method. If the SoC in the intelligent driving domain controller fails but the MCU survives, the MCU can control the vehicle. If both the SoC and the MCU in the intelligent driving domain controller fail, the vehicle can be controlled by sensors or end-side devices. This reduces the complexity of redundant backup solutions for implementing intelligent driving functions, avoids the complexities associated with deploying two intelligent driving domain controllers, and reduces development costs.

[0071] The intelligent driving domain controller described in the embodiments of this application can be a domain controller for various devices that implement functions such as perception, positioning, path planning, and decision-making control, including but not limited to intelligent driving domain controllers on vehicles (such as vehicles) and domain controllers on terminal devices. For example, vehicles can include but are not limited to ground-based vehicles such as cars, buses, motorcycles, locomotives, and subways; surface-based vehicles such as ships and submarines; and aerial vehicles such as airplanes and helicopters. Terminal devices can include but are not limited to artificial intelligence (AI) devices.

[0072] Exemplarily, FIG3 shows a schematic diagram of the architecture of a communication system for an intelligent driving method application provided in an embodiment of the present application. Optionally, the communication system 300 can be installed on the above-mentioned vehicle or on a terminal device. The embodiment of the present application takes the installation on a vehicle as an example to illustrate the architecture of the communication system 300. Optionally, the vehicle can be a conventional vehicle or an autonomous driving vehicle for transportation. An autonomous driving vehicle may also be referred to as an unmanned vehicle or an intelligent driving vehicle, etc., which can travel in manual mode, fully autonomous mode or partially autonomous mode. When configured to travel in fully autonomous mode or partially autonomous mode, the autonomous driving vehicle can travel autonomously in a geographical area with little or no control input from the driver.

[0073] As shown in FIG3 , the communication system 300 includes an intelligent driving domain controller 301 and one or more sensors 302 .

[0074] The intelligent driving domain controller 301 manages multiple electronic control units (ECUs) within the intelligent driving domain to implement autonomous driving-related perception, decision-making, and control functions. Different ECUs can perform different functions, such as the engine ECU controlling the engine's air intake, fuel injection, and ignition timing, while the air conditioning ECU controls vehicle temperature.

[0075] The intelligent driving domain controller 301 includes a SoC 3010 and an MCU 3011. The SoC 3010 can be used to perform complex calculations for various intelligent driving-related algorithms, including but not limited to perception, fusion, positioning, planning and control. In some implementations, the SoC 3010 can be a circuit with instruction reading and execution capabilities, such as a CPU, a microprocessor unit (MPU), a graphics processing unit (GPU), a digital signal processor (DSP), an analog-to-digital converter (ADC), a digital-to-analog converter (DAC), a modem, etc. In another implementation, the SoC 3010 can implement certain functions through the logical relationships of hardware circuits, and the logical relationships of the hardware circuits can be fixed or reconfigurable.

[0076] MCU 3011 is primarily used to connect various communication links used to transmit vehicle control commands, such as communication link 303. MCU 3011 can send vehicle control commands to communication link 303 to control the vehicle. For example, as shown in FIG3 , communication link 303 can be implemented as a controller area network with flexible data rate (CANFD) bus, such as CANFD 1 and CANFD 2. Of course, in other implementations, the communication link can also be implemented as a communication link generated by other communication methods, such as Ethernet.

[0077] In some embodiments, the power supply of SoC 3010 (e.g., a complex programmable logic device (CPLD)) can be controlled by MCU 3011. MCU 3011 can be responsible for detecting the operating status of SoC 3010 and performing various operations such as powering on and off SoC 3010. Of course, in other embodiments, the power supply of SoC 3010 can also be directly controlled by SoC 3010 itself, and this embodiment of the present application is not limited to this.

[0078] Exemplarily, the one or more sensors 302 may include but are not limited to one or more types of cameras (such as an intelligent front camera (IFC) 3020), radars (such as a forward radar 3021, a lidar 3022, a millimeter-wave radar 3023, an ultrasonic radar, etc.), an inertial measurement unit (IMU), a global positioning system (GPS), etc.

[0079] Optionally, some of the one or more sensors 302 are connected to the SoC 3010, while others are connected to the MCU 3011. Optionally, the same sensor may be connected to only one of the SoC 3010 and the MCU 3011, or may be connected to both the SoC 3010 and the MCU 3011. In some embodiments, the number of sensors connected to the SoC 3010 is greater than the number of sensors connected to the MCU 3011, which facilitates the SoC 3010 in performing various computing operations. Of course, in other embodiments, the number of sensors connected to the SoC 3010 may be less than or equal to the number of sensors connected to the MCU 3011, and this is not limited in this embodiment of the present application.

[0080] In some embodiments, the one or more sensors may include a target sensor. The target sensor can be any sensor with computing capabilities, including but not limited to a camera (such as IFC 3020), a high-computing radar, etc. Optionally, the number of target sensors may be one or more. It will be appreciated that FIG3 illustrates the target sensor as IFC 3020. The IFC 3020 not only includes traditional devices such as a camera module, but also a small computing unit with sufficient computing power to implement functions such as obstacle detection. This allows the IFC to have sufficient computing power. If both the SoC and the MCU fail, the IFC's computing power can be used to calculate vehicle control commands. The IFC is also connected to the communication link that transmits vehicle control commands. This allows the IFC to send its own vehicle control commands or those from the SoC to the communication link that transmits vehicle control commands, and then send the vehicle control commands to the actuators to control the vehicle. Furthermore, the IFC can exchange data with the MCU via the communication link that transmits vehicle control commands, thereby transmitting sensory data to the MCU.

[0081] In some embodiments of the present application, the target sensor may also be connected to various communication links for transmitting vehicle control commands, such as communication link 303. Similarly, the target sensor may also send vehicle control commands to communication link 303 to achieve vehicle control.

[0082] In some other embodiments of the present application, one or more sensors 302 may further include a first sensor, and the target sensor may further establish a connection with the first sensor to receive the perception data of the first sensor through the established connection. Optionally, the first sensor may be any one of the one or more sensors 302 except the target sensor, and the first sensor and the target sensor may be sensors of the same type or sensors of different types. Optionally, the number of first sensors may also be one or more. FIG3 takes the forward radar 3021 as an example of the first sensor. Among them, the forward radar 3021 is a forward obstacle sensor with short-range perception capabilities in intelligent driving, and can be used as a perception module to provide obstacle recognition information. In this way, the first sensor establishes a connection with the target sensor. Subsequently, when the target sensor controls the vehicle, it can receive the perception data of the first sensor based on the established connection, and then generate vehicle control instructions based on the perception data of the first sensor to achieve control of the vehicle.

[0083] Optionally, the SoC 3010, MCU 3011, sensor, target sensor, and first sensor may be connected to each other via an in-vehicle bus. The bus may be a controller area network (CAN) bus, a wired communication line such as Ethernet, a local interconnect network (LIN) bus, a media-oriented system transport (MOST) bus, or FlexRay, or a line generated by a wireless communication module such as wireless fidelity (Wi-Fi), Bluetooth, or ZigBee.

[0084] In some embodiments, the communication system 300 may also include one or more other domain controllers and / or one or more ECUs (such as but not limited to air suspension, chassis, mobile phone keys, etc.), such as the VCU 304 shown in Figure 3. Among them, the one or more domain controllers and / or the one or more ECUs can also be connected to the communication link 303 to achieve information delivery. For example, the VCU 304 can be connected to the communication link 303, receive vehicle control instructions from the communication link 303, and send the vehicle control instructions to the actuator (such as the chassis) for execution to achieve vehicle control, such as but not limited to acceleration / deceleration, lane change, steering, braking, or warnings. In other embodiments, the actuator can also be directly connected to the communication link 303, receive vehicle control instructions from the communication link 303, and execute the vehicle control instructions to achieve vehicle control.

[0085] It is understandable that the communication architecture shown in FIG3 is merely an example. In other embodiments, the communication system shown in FIG3 may further include other devices that are not shown in the figure.

[0086] 4 shows a schematic diagram of the structure of a target sensor provided by an embodiment of the present application. The target sensor includes at least one processor 401, a communication line 402, a memory 403 and at least one communication interface 404.

[0087] The processor 401 may be an MCU, a general-purpose CPU, a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the program of the present application.

[0088] The communication link 402 may include a pathway for transmitting information between the aforementioned components.

[0089] The communication interface 404 is used to communicate with other devices (eg, the SoC 3010 and the MCU 3011 shown in FIG3 ). In the embodiment of the present application, the communication interface 404 may be a module, a circuit, a bus, an interface, a transceiver, or other devices capable of implementing communication functions.

[0090] Memory 403 may be a read-only memory (ROM), random access memory (RAM), or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer. Memory 403 may be independent and connected to processor 401 via communication line 402. Memory 403 may also be integrated with processor 401.

[0091] The memory 403 stores computer-executable instructions for implementing the solution of the present application. The processor 401 is configured to execute the computer-executable instructions stored in the memory 403, thereby implementing the methods provided in the following embodiments of the present application.

[0092] In other embodiments of the present application, the target sensor may include more or fewer components than those shown in FIG4 , or combine certain components, or split certain components, or replace certain components, or arrange the components differently. The components shown in the figure can be implemented in hardware, software, or a combination of software and hardware. For example, if the target sensor is a camera, the structure shown in FIG4 may also include a lens, an image sensor, etc. For another example, if the target sensor is a high-computing-power radar, the structure shown in FIG4 may also include a transmitter, an antenna, etc.

[0093] The following describes the intelligent driving method provided in an embodiment of the present application in conjunction with the communication system shown in FIG3 .

[0094] In some embodiments, as shown in FIG5 , the intelligent driving method may include the following steps:

[0095] S501. SoC receives first perception data from M sensors.

[0096] Wherein, M is an integer greater than or equal to 2. Optionally, the M sensors may be some or all of the sensors connected to the SoC and the sensors connected to the MCU. In some embodiments, the M sensors may include a forward-facing radar and an IFC.

[0097] Optionally, the SoC can continue to receive the first sensing data from the M sensors regardless of whether the SoC fails or not. It will be understood that in this embodiment of the present application, failure can be referred to as an anomaly or a fault. In the event of a device failure, the device is unable to complete various operations that are required to be performed.

[0098] In some embodiments, in the scenario of MCU failure, as shown in (1) in Figure 5, the intelligent driving method may further include steps S502 to S503.

[0099] S502: The SoC sends first information to a target sensor based on the first sensing data. Correspondingly, the target sensor receives the first information from the SoC.

[0100] The target sensor may be one of the M sensors, such as an IFC. Optionally, the number of target sensors may be one or more. When there are multiple target sensors, the SoC may select any one of them to send the first information, which is not limited in this embodiment of the present application.

[0101] In some embodiments, the first information may be a perception result calculated based on the first perception data. In other embodiments, the first information may be a vehicle control instruction.

[0102] It can be understood that in this scenario, the target sensor is in a non-failed state.

[0103] S503: The target sensor outputs a first vehicle control instruction according to the first information.

[0104] The first vehicle control instruction can be used to control the vehicle. It is understood that the vehicle control instructions described in the embodiments of the present application are distinguished by "first", "second", etc., which is only used to illustrate the different sources of the vehicle control instructions and does not constitute a limitation on their content. The content contained in different vehicle control instructions can be the same or different.

[0105] In some embodiments, the target sensor can send the output first vehicle control instruction to a communication link 303 such as that shown in Figure 3, and send the first vehicle control instruction to the VCU 304 through the communication link 303 (such as a CAN bus, etc.), or send it to the actuator corresponding to the first vehicle control instruction to achieve control of the vehicle.

[0106] Optionally, in the above scenario, in some embodiments, if the MCU fails for longer than a first preset time, the SoC may further send a second message to the target sensor to stop the vehicle or cease controlling the vehicle. Accordingly, the target sensor may also output a corresponding vehicle control command based on the second message to stop the vehicle or cease controlling the vehicle (i.e., exit control of the vehicle and put the vehicle into human-driven mode).

[0107] In some embodiments, the preset durations described in this application can be determined based on the computing power of the SoC, MCU, and target sensor. For example, when the computing power of the SoC is the largest and the computing power of the target sensor is the smallest, the first preset duration (e.g., 20 seconds) can be greater than the second preset duration (e.g., 15 seconds), and the second preset duration can be greater than the third preset duration (e.g., 10 seconds). In this way, when a device with a larger computing power controls the vehicle, a longer control time is set, and when a device with a smaller computing power controls the vehicle, a relatively shorter control time is set. This ensures the safety of intelligent driving while giving the driver a certain amount of reaction time to achieve safe takeover. Of course, in other embodiments, each preset duration can also have other setting methods, which can be the same or different, and the embodiments of this application do not limit this.

[0108] Optionally, in the scenario where the above-mentioned MCU fails, the vehicle's autonomous driving level can be reduced by two levels, such as from L5 to L3, and this embodiment of the present application does not limit this.

[0109] Based on this technical solution, the SoC acquires sensor data and calculates perception results or vehicle control commands based on this data. In the event of an MCU failure, the SoC can output vehicle control commands through the target sensor, thereby achieving vehicle control, such as autonomous driving. This provides redundant backup for intelligent driving functions, avoiding the complexities of deploying two intelligent driving domain controllers and reducing development costs.

[0110] It is understandable that the intelligent driving methods described in the various embodiments of the present application can be used in combination if there is no conflict.

[0111] In other embodiments, in a scenario where the MCU is not failed, as shown in (2) in FIG5 , the intelligent driving method may further include steps S504 to S505.

[0112] S504: The SoC sends first information to the MCU based on the first sensing data. Correspondingly, the MCU receives the first information from the SoC.

[0113] Optionally, in this scenario, the target sensor may or may not be in a failed state. In this way, the SoC preferentially sends the first information to the MCU to achieve control of the vehicle. Since the SoC and the MCU are both in the intelligent driving domain controller, the communication link is shorter than the communication link for transmitting the first information to the target sensor, and the computing power of the MCU is better than that of the target sensor. This can save signal transmission time, increase computing speed, and thus improve vehicle control efficiency and control accuracy.

[0114] Of course, in other embodiments, when both the MCU and the target sensor are not failed, the SoC may also preferentially send the first information to the target sensor, which is not limited in the embodiments of the present application.

[0115] S505. The MCU outputs a second vehicle control instruction based on the first information.

[0116] The second vehicle control instruction is used to control the vehicle. In some embodiments, the MCU may also output the second vehicle control instruction to a communication link 303, such as that shown in FIG3 , and transmit the second vehicle control instruction to the VCU 304 or an actuator corresponding to the second vehicle control instruction via the communication link 303 to achieve vehicle control.

[0117] Optionally, in this scenario, when both the SoC and the MCU are not failed, the SoC may also send a first synchronization signal and a first compensation signal to the target sensor, and the MCU may also send a second synchronization signal and a second compensation signal to the target sensor. Accordingly, the target sensor may receive the aforementioned first synchronization signal, first compensation signal, second synchronization signal, second compensation signal, etc. The target sensor may perform time synchronization based on the first synchronization signal and compensate for errors in the perception data of the target sensor caused by vehicle motion based on the first compensation signal. Optionally, the target sensor may also compensate for errors in the perception data of other sensors caused by vehicle motion based on the first compensation signal.

[0118] Of course, the SoC can also send a first synchronization signal and a first compensation signal to other sensors (such as radar, etc.) other than the target sensor, and the MCU can also send a second synchronization signal and a second compensation signal to other sensors other than the target sensor. Correspondingly, the other sensor can also receive the aforementioned first synchronization signal, first compensation signal, second synchronization signal, second compensation signal, etc. The other sensor can perform time synchronization based on the first synchronization signal and compensate for the error in its own perception data caused by vehicle motion based on the first compensation signal.

[0119] Optionally, in other implementations, the SoC may also send the SoC status to the sensor. Similarly, the MCU may also send the MCU status to the sensor.

[0120] It can be understood that in the above implementation, the default use of the synchronization signal and compensation signal sent by the SoC is taken as an example. In other embodiments, the default use of the synchronization signal and compensation signal sent by the MCU may also be adopted. The embodiments of the present application do not limit this.

[0121] It should also be understood that the use of terms such as "first" and "second" or the lack of such terms to distinguish the synchronization signals and compensation signals described in the embodiments of this application merely illustrates the different sources of the synchronization signals and compensation signals and does not limit their content. The contents of the signals may be the same or different. For example, each compensation signal may include information such as vehicle position and speed.

[0122] Optionally, in an embodiment of the present application, whether the MCU and / or target sensor has failed can be determined by the SoC itself. For example, the SoC can monitor the MCU's heartbeat to determine whether the MCU has failed. In this way, if the SoC's power supply is controlled by the MCU, if the SoC detects that the MCU has failed, it can promptly instruct the power supply (such as the CPLD) to continue powering the SoC to ensure that the SoC can operate normally. Similarly, the SoC can also monitor the heartbeat of the target sensor to determine whether the target sensor has failed. Of course, other devices can also notify the SoC whether the MCU and / or target sensor has failed. For example, the target sensor can monitor the MCU's heartbeat and, upon determining that the MCU has failed, send an indication indicating the MCU has failed to the SoC. The MCU can monitor the target sensor's heartbeat and, upon determining that the target sensor has failed, send an indication indicating the target sensor has failed to the SoC. In this way, the target sensor can promptly switch the source of the synchronization signal and compensation signal to ensure the accuracy of the target sensor's perception data. Of course, the aforementioned other devices can also be devices other than the target sensor and the MCU, and this embodiment of the present application is not limited to this.

[0123] Similarly, in the embodiments of the present application, whether the SoC and / or target sensor is faulty can be determined by the MCU by monitoring heartbeats, etc., or by receiving indications from other devices. Whether the SoC and / or target sensor is faulty can be determined by all target sensors by monitoring heartbeats, etc., or by receiving indications from other devices.

[0124] Optionally, in the scenario where the MCU does not fail, because the computing power of the MCU is superior to that of the target sensor, the vehicle's autonomous driving level can be downgraded by one level, such as from L5 to L4. Of course, in other implementations, the vehicle's autonomous driving level can also have other settings, and this embodiment of the application does not limit this.

[0125] Based on the above technical solution, after the SoC obtains the sensor's perception data, it calculates the perception result or vehicle control command based on the perception data. In the scenario where the MCU has not failed, the vehicle control command is outputted through the MCU first, thereby achieving vehicle control, such as achieving automatic driving of the vehicle. This not only achieves redundant backup of the intelligent driving function, but also avoids the complex problems caused by deploying two intelligent driving domain controllers, thereby reducing development costs. In addition, the vehicle control command is outputted through the MCU rather than the target sensor first. Since the SoC and the MCU are both in the intelligent driving domain controller, the communication link is shorter than the communication link for transmitting the first information to the target sensor, and the computing power of the MCU is better than that of the target sensor. This can save signal transmission time, increase computing speed, and thus improve vehicle control efficiency and control accuracy.

[0126] In some other embodiments, as shown in FIG6 , the intelligent driving method may include the following steps:

[0127] S601. The MCU receives second perception data from N sensors.

[0128] Wherein, N is less than M and is a positive integer. Optionally, the N sensors may be some or all of the sensors connected to the MCU. Optionally, the N sensors may or may not overlap with the M sensors.

[0129] Optionally, when the MCU fails or not, the MCU can receive the second perception data from the N sensors.

[0130] S602: When the SoC fails, the MCU outputs a third vehicle control instruction based on the second perception data.

[0131] The third vehicle control instruction can be used to control the vehicle. Similarly, the MCU can also send the output third vehicle control instruction to a communication link 303 such as shown in FIG3 , and send the third vehicle control instruction to the VCU 304 or the actuator corresponding to the third vehicle control instruction via the communication link 303 to achieve vehicle control.

[0132] Optionally, in some embodiments, when the SoC fails for more than a second preset time, the MCU may further control the vehicle to stop or cease controlling the vehicle. Optionally, when controlling the vehicle to stop, the MCU may further perform this operation based on the second sensing data.

[0133] Optionally, in this scenario, if the SoC fails, the MCU can also send a second synchronization signal and a second compensation signal to the target sensor. Accordingly, the target sensor can receive the aforementioned second synchronization signal and second compensation signal, perform time synchronization based on the second synchronization signal, and compensate for errors in the target sensor's perception data caused by vehicle motion based on the second compensation signal. Optionally, the target sensor can also compensate for errors in the perception data of other sensors caused by vehicle motion based on the second compensation signal.

[0134] Similarly, in this scenario, the MCU can also send a second synchronization signal and a second compensation signal to other sensors besides the target sensor. Accordingly, these other sensors can also receive the aforementioned second synchronization signal and second compensation signal. These other sensors can synchronize their time based on the second synchronization signal and compensate for errors in their own sensor data caused by vehicle motion based on the second compensation signal.

[0135] Based on this technical solution, after the MCU acquires sensor data, if the SoC fails, it can calculate vehicle control instructions based on this data to achieve vehicle control. This enables redundant backup of intelligent driving functions, avoiding the complexities of deploying two intelligent driving domain controllers and reducing development costs.

[0136] In some embodiments, if the SoC is not faulty, the MCU can also send the second sensory data to the SoC, so that the SoC can output the first information in combination with the second sensory data. In this way, if the SoC is not faulty, the MCU will send the received sensory data to the SoC, and the SoC will perform the calculations on the sensory data. Because the SoC has higher computing power than the MCU, this can be more efficient and obtain more accurate vehicle control commands, thereby improving vehicle control efficiency and control accuracy.

[0137] It should be understood that the above embodiment uses the MCU to control the vehicle in the event of a SoC failure. In other embodiments, the target sensor can also control the vehicle in the event of a SoC failure. For example, the target sensor can receive sensing data from the first sensor and output vehicle control commands based on the sensing data to control the vehicle.

[0138] In some further embodiments, as shown in FIG7 , the intelligent driving method may include the following steps:

[0139] S701: When both the SoC and the MCU fail, the target sensor receives sensing data from the first sensor.

[0140] For example, the target sensor can receive perception data from the first sensor based on its connection with the first sensor. For example, the first sensor can be a forward-facing radar. Optionally, the number of first sensors can be one or more, and the target sensor can receive perception data from some or all of the first sensors.

[0141] It is understood that the embodiment shown in FIG7 is based on an example in which the target sensor controls the vehicle based on its own sensing data and the sensing data of the first sensor (i.e., the sensing data of a sensor other than itself). This can improve the accuracy of vehicle control. Of course, in other embodiments, the target sensor can also control the vehicle based solely on its own sensing data, and this embodiment of the application is not limited to this.

[0142] S702: The target sensor outputs a vehicle control instruction based on the perception data of the target sensor and the perception data of the first sensor.

[0143] The vehicle control command is used to control the vehicle. In some embodiments, after step S702, the target sensor may send the outputted vehicle control command to a communication link 303, such as that shown in FIG3 , and the vehicle control command may be sent to the VCU 304 or an actuator corresponding to the vehicle control command via the communication link to achieve vehicle control.

[0144] Optionally, in some embodiments, the target sensor may also obtain a compensation signal based on a communication link 303 (such as a CAN bus) such as shown in FIG3 , and compensate for errors in the perception data of the target sensor caused by the movement of the vehicle based on the compensation signal. In this way, the calculation results of the target sensor can be made more accurate, thereby improving the control accuracy of the vehicle. Optionally, the target sensor may also compensate for errors in the perception data of the first sensor caused by the movement of the vehicle based on the compensation signal. Of course, the target sensor may also send the compensation signal to the first sensor, and the first sensor may compensate for errors in the perception data of the first sensor caused by the movement of the vehicle.

[0145] In some embodiments, the target sensor may stop controlling the vehicle or control the vehicle to stop if both the SoC and the MCU fail for a predetermined period of time (e.g., a third predetermined period of time). Optionally, when controlling the vehicle to stop, the target sensor may control the vehicle to stop based on at least one of its own sensing data and the sensing data of the first sensor.

[0146] It is understood that this embodiment uses the example of the target sensor outputting vehicle control commands only when both the SoC and the MCU are invalid. This allows for vehicle control, such as maintaining autonomous driving and backing up intelligent driving functions, even when both the SoC and the MCU are invalid, while also reducing the power consumption of IFC real-time computing. Of course, in other embodiments, the smart sensor may also output vehicle control commands when the SoC or the MCU is valid. When the VCU or actuator receives multiple vehicle control commands and determines that the SoC or the MCU is valid, it may ignore the smart sensor's vehicle control commands and execute the SoC's or MCU's vehicle control commands.

[0147] Optionally, in a scenario where both the SoC and MCU fail, the vehicle is controlled solely by the target sensor, which has the lowest computing power. Therefore, the vehicle's autonomous driving level can be reduced by three levels, such as from L5 to L2. Of course, in other embodiments, the vehicle's autonomous driving level can also be set differently, and this embodiment of the present application is not intended to limit this.

[0148] Based on this technical solution, if both the SoC and MCU fail, the target sensor receives the perception data from connected sensors and uses this data to control the vehicle, such as intelligent driving. This provides redundant backup for intelligent driving functions. Furthermore, the deployment of two intelligent driving domain controllers is eliminated, avoiding the complexities inherent in deploying two domain controllers and reducing development costs.

[0149] It is understood that in the above embodiment, the example of the vehicle being controlled by sensors when both the SoC and the MCU fail is used. In other embodiments, the sensors can also be implemented as other devices, such as: end-side devices. Exemplarily, the end-side devices may include but are not limited to servers, desktop computers, laptop computers, handheld computers, notebook computers, ultra-mobile personal computers (UMPCs), artificial intelligence (AI) devices, smart home devices and / or smart city devices. The embodiments of the present application do not impose any special restrictions on the specific type of the end-side devices.

[0150] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. It is understandable that in order to realize the above functions, the intelligent driving domain controller and / or sensor includes hardware structures and / or software modules corresponding to the execution of each function. In combination with the units and algorithm steps of each example described in the embodiments disclosed in this application, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or computer-driven hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiment of the present application.

[0151] The present application is an embodiment that can divide the functional modules of the intelligent driving domain controller and / or sensor according to the above method example. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of units in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0152] As shown in Figure 8, a schematic diagram of the structure of a sensor provided in an embodiment of the present application is provided. The sensor 800 can be used to implement the methods performed by the target sensors described in the above method embodiments. For example, the sensor can include: a communication unit 801 and a processing unit 802.

[0153] The communication unit 801 is used to support the sensor 800 in performing the communication function as described in any one of Figures 1 to 7. The processing unit 802 is used to support the sensor 800 in performing the processing function as described in any one of Figures 1 to 7.

[0154] Optionally, the sensor 800 shown in FIG8 may further include a storage unit 803 storing a program or instruction. When the processing unit 802 executes the program or instruction, the sensor 800 shown in FIG8 may execute the method executed by the target sensor in the above method embodiment.

[0155] The technical effects of the sensor 800 shown in FIG8 can be referenced to the technical effects described in the above method embodiments and will not be repeated here. The processing unit 802 involved in the sensor 800 shown in FIG8 can be implemented by a processor or processor-related circuit components, and can be a processor or processing module. The communication unit 801 can be implemented by a transceiver or transceiver-related circuit components, and can be a transceiver or transceiver module.

[0156] An embodiment of the present application also provides a chip system, which includes at least one processor and at least one interface circuit. The processor and the interface circuit can be interconnected through lines. For example, the interface circuit can be used to receive signals from other devices. For another example, the interface circuit can be used to send signals to other devices (such as processors). Exemplarily, the interface circuit can read instructions stored in the memory and send the instructions to the processor. When the instructions are executed by the processor, the sensor can execute the various steps performed by the target sensor in the above embodiment, or the intelligent driving domain controller can execute the various steps performed by the intelligent driving domain controller in the above embodiment. Of course, the chip system can also include other discrete devices, which is not specifically limited in the embodiment of the present application.

[0157] The present application also provides a computer storage medium that stores computer instructions. When the computer instructions are executed on a sensor, the sensor executes the method described in the above method embodiment. Alternatively, when the computer instructions are executed on an intelligent driving domain controller, the intelligent driving domain controller executes the method described in the above method embodiment. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0158] An embodiment of the present application provides a computer program product, which includes: a computer program or instructions, which, when executed on a computer, causes the computer to execute the method described in the above method embodiment.

[0159] Among them, the sensors, intelligent driving domain controller, computer storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0160] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0161] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The various embodiments can be combined with each other or referenced to each other without conflict. The device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0162] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0163] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0164] The above content is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. An intelligent driving method, characterized in that, An intelligent driving domain controller applied to a vehicle, the intelligent driving domain controller includes a system-on-chip (SoC) and a microcontroller unit (MCU), and the method includes: The SoC receives first perception data from M sensors, where M is greater than or equal to 2; In the case where the MCU fails, the SoC sends first information to a target sensor based on the first perception data, so that the target sensor outputs a first vehicle control instruction to control the vehicle, and the target sensor is one of the M sensors.

2. The method according to claim 1, wherein The method further includes: In the case where the MCU does not fail, the SoC sends the first information to the MCU based on the first perception data, so that the MCU outputs a second vehicle control instruction to control the vehicle.

3. The method according to claim 1 or 2, characterized in that, The method further includes: The MCU receives second perception data from N sensors, where N is less than M; In the case where the SoC fails, the MCU outputs a third vehicle control instruction to control the vehicle based on the second perception data.

4. The method according to any one of claims 1 to 3, characterized in that The first information is a vehicle control instruction, or the first information is a perception result calculated based on the first perception data.

5. The method according to any one of claims 1-4, characterized in that, The method further includes: In the case where the MCU fails for more than a first preset duration, the SoC sends second information to the target sensor to control the vehicle to stop or stop controlling the vehicle.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: In the case where the SoC fails for more than a second preset duration, the MCU controls the vehicle to stop or stop controlling the vehicle.

7. The method according to any one of claims 1-6, characterized in that, The M sensors at least include a forward radar and an intelligent front view camera (IFC), and the target sensor is the IFC.

8. An intelligent driving method, characterized in that, A target sensor applied to a vehicle, the vehicle further includes an intelligent driving domain controller, and the method includes: In the case where both the SoC and the MCU of the intelligent driving domain controller fail, receive perception data from a first sensor; Output a vehicle control instruction to control the vehicle based on the perception data of the target sensor and the perception data of the first sensor.

9. The method according to claim 8, characterized in that, The method further includes: In the case where only the MCU fails, receive first information from the SoC; Output another vehicle control instruction to control the vehicle according to the first information.

10. The method according to claim 8 or 9, characterized in that After outputting the vehicle control instruction to control the vehicle based on the perception data of the target sensor and the perception data of the first sensor, the method further includes: Send the vehicle control instruction to an actuator corresponding to the vehicle control instruction through a controller area network (CAN) bus.

11. The method according to claim 9 or 10, characterized in that, The first information is the another vehicle control instruction, or the first information is a perception result calculated based on the perception data of M sensors, where M is greater than or equal to 2, and the M sensors include the target sensor and the first sensor.

12. The method according to any one of claims 8-11, characterized in that, Before outputting the vehicle control instruction to control the vehicle based on the perception data of the target sensor and the perception data of the first sensor, the method further includes: Obtain a compensation signal through the CAN bus, and the compensation signal is used to compensate for the error of the perception data of the target sensor caused by the movement of the vehicle.

13. The method according to any one of claims 8-11, characterized in that, The method further includes: When neither the SoC nor the MCU fails, receive a first synchronization signal and a first compensation signal from the SoC, and receive a second synchronization signal and a second compensation signal from the MCU; Perform time synchronization based on the first synchronization signal, and compensate for the error of the sensed data of the target sensor caused by the vehicle movement based on the first compensation signal; When the SoC fails, receive the second synchronization signal and the second compensation signal from the MCU; Perform time synchronization based on the second synchronization signal, and compensate for the error of the sensed data of the target sensor caused by the vehicle movement based on the second compensation signal.

14. The method according to any one of claims 8-13, characterized in that The method further includes: When both the SoC and the MCU have failed for more than a preset duration, stop controlling the vehicle or control the vehicle to stop based on the sensed data of the target sensor and the sensed data of the first sensor.

15. The method according to any one of claims 8 - 14, characterized in that, The target sensor is an IFC, and the first sensor is a forward radar.

16. An intelligent driving domain controller, characterized in that, Comprising an SoC and an MCU, the SoC is used to execute the method executed by the SoC according to any one of claims 1-7, and the MCU is used to execute the method executed by the MCU according to any one of claims 1-7.

17. A sensor, characterized in that, Including a processor, the processor is used to execute a computer program or instruction so that the method according to any one of claims 8-15 is executed.

18. An intelligent driving system, characterized in that, Including the intelligent driving domain controller according to claim 16 and the sensor according to claim 17.

19. A vehicle, characterized in that, Including the intelligent driving domain controller according to claim 16 and the sensor according to claim 17.

Citation Information

Patent Citations

  • Intelligent driving method, intelligent driving domain controller and sensor

    CN117922610A

  • Automobile electric control system, automatic driving control method and automobile

    CN112429012A

  • Vehicle headlamp self-adaptive height adjusting system and method and vehicle

    CN114771399A

  • Driving function safety framework and vehicle

    CN115782906A

  • Intelligent driving power distribution system, intelligent driving perception method and storage medium

    CN116279210A

Cited By

  • Vehicle component control method, vehicle, storage medium and program product

    CN121019608A