Vehicle interface system, device, storage medium and program product

By designing redundant vehicle interface modules for hot backup in the vehicle interface system, the low security problem caused by the need for manual intervention due to module malfunctions in traditional systems is solved, and safe and reliable control is achieved under abnormal conditions.

WO2026092017A1PCT designated stage Publication Date: 2026-05-07BEIJING VOYAGER TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING VOYAGER TECH CO LTD
Filing Date
2025-09-25
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

In autonomous driving and assisted driving modes, traditional vehicle interface systems require manual intervention when modules malfunction, resulting in low intelligence and vulnerability to safety issues due to driver error.

Method used

Design a vehicle interface system comprising first and second vehicle interface modules. Utilize a redundant module to generate control commands in place of the main module in case of failure, achieving hot backup and ensuring vehicle safety and robustness.

Benefits of technology

The hot backup mechanism enhances the safety and reliability of the vehicle when the interface module malfunctions, avoids the risk of misoperation caused by human intervention, and improves the safety performance of autonomous driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025124147_07052026_PF_FP_ABST
    Figure CN2025124147_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a vehicle interface system (120), a device, a storage medium and a program product. The vehicle interface system (120) comprises a first vehicle interface module (145-1) and a second vehicle interface module (145-2). The first vehicle interface module (145-1) is configured to receive a first control instruction from an autonomous driving system of a vehicle, and on the first control instruction, generate a second control instruction used for controlling at least one component of the vehicle. The second vehicle interface module (145-2) is configured to receive, in parallel with the first vehicle interface module (145-1), the first control instruction from the autonomous driving system; and in response to the occurrence of an anomaly in the first vehicle interface module (145-1), to replace the first vehicle interface module (145-1) to generate a third control instruction on the basis of the first control instruction, the content of the third control instruction being the same as that of the second control instruction. In this way, when the first vehicle interface module (145-1) has had an anomaly, the system can use the second vehicle interface module (145-2) in place of the first vehicle interface module (145-1) to complete the generation of the control instruction, thereby improving the safety of vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle interface systems, devices, storage media, and software products

[0001] This application claims priority to Chinese Patent Application No. 202411535335.3, filed on October 30, 2024, entitled "Vehicle Interface System, Device, Storage Medium and Program Product", the entire contents of which are incorporated herein by reference. Technical Field

[0002] The exemplary embodiments disclosed herein generally relate to the field of autonomous driving, and particularly to vehicle interface systems, devices, computer-readable storage media, and computer program products. Background Technology

[0003] With the development of computer technology, autonomous driving and assisted driving technologies have emerged to reduce the demands on drivers and free them from certain driving responsibilities. Typically, vehicles can assist drivers by using road condition information collected by onboard sensors or other sensing devices, or they can use control units to process this information and directly control the vehicle. While improving driver convenience and the driving experience, enhancing vehicle safety and robustness in autonomous driving and assisted driving modes is a crucial consideration. Summary of the Invention

[0004] In a first aspect of this disclosure, a vehicle interface system is provided. The system includes: a first vehicle interface module configured to receive a first control command from an autonomous driving system of a vehicle, and to generate a second control command based on the first control command for controlling at least one component of the vehicle; and a second vehicle interface module configured to receive the first control command from the autonomous driving system in parallel with the first vehicle interface module, and to generate the second control command based on the first control command in place of the first vehicle interface module in response to an anomaly occurring in the first vehicle interface module.

[0005] In a second aspect of this disclosure, an electronic device is provided, comprising: a memory and a processor; wherein the memory is configured to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement a first vehicle interface module and / or a second vehicle interface module in a vehicle interface system according to a first aspect of this disclosure.

[0006] In a third aspect of this disclosure, a computer-readable storage medium is provided having one or more computer instructions stored thereon, wherein the one or more computer instructions are executed by a processor to implement a first vehicle interface module and / or a second vehicle interface module in a vehicle interface system according to a first aspect of this disclosure.

[0007] In a fourth aspect of this disclosure, a computer program product is provided, comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement a first vehicle interface module and / or a second vehicle interface module in a vehicle interface system according to a first aspect of this disclosure.

[0008] It should be understood that the content described in this content section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0009] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:

[0010] Figure 1 shows a schematic diagram of an example environment in which embodiments of the present disclosure may be implemented;

[0011] Figure 2 shows a schematic diagram of an example framework of a vehicle system according to some embodiments of the present disclosure;

[0012] Figure 3 illustrates a schematic diagram of an example framework of a vehicle interface system according to some embodiments of the present disclosure; and

[0013] Figure 4 shows a block diagram of an electronic device capable of implementing several embodiments of the present disclosure. Detailed Implementation

[0014] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0015] It should be noted that the headings of any section / subsection provided herein are not limiting. Various embodiments are described throughout this document, and embodiments of any type may be included under any section / subsection. Furthermore, embodiments described in any section / subsection may be combined in any way with any other embodiments described in the same section / subsection and / or different sections / subsections.

[0016] In the description of embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may also be included below. The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.

[0017] The embodiments of this disclosure may involve user data, data acquisition, and / or use. All of these aspects comply with applicable laws, regulations, and relevant provisions. In the embodiments of this disclosure, all data collection, acquisition, processing, manipulation, forwarding, and use are conducted with the user's knowledge and confirmation. Accordingly, in implementing the embodiments of this disclosure, the type, scope of use, and usage scenarios of any data or information that may be involved should be communicated to the user and their authorization obtained in accordance with relevant laws and regulations through appropriate means. The specific methods of notification and / or authorization may vary depending on the actual situation and application scenario, and the scope of this disclosure is not limited in this respect.

[0018] In this specification and the embodiments, any processing of personal information will be carried out only under the premise of legality (such as obtaining the consent of the personal information subject, or being necessary for the performance of a contract), and will only be carried out within the scope stipulated or agreed upon. A user's refusal to process personal information other than that necessary for basic functions will not affect the user's use of basic functions.

[0019] As mentioned above, with the development of computer technology, autonomous driving and assisted driving technologies have emerged to reduce the demands on drivers and free them from certain driving responsibilities. Typically, vehicles can assist drivers by collecting road condition information from onboard sensors or other sensing devices, or they can use control units to process this information and directly control the vehicle. However, while improving driver convenience and the driving experience, it is worthwhile to consider how to make vehicles safer and enhance their safety performance in autonomous driving and assisted driving modes. In traditional vehicle interface systems, when the vehicle interface module malfunctions, control of the vehicle is still achieved through methods such as manual intervention. This approach not only has a low level of intelligence but also easily leads to driver errors due to panic, which in turn affects the vehicle's safety performance.

[0020] Embodiments of this disclosure propose a vehicle interface system. The system includes: a first vehicle interface module configured to receive a first control command from an autonomous driving system of a vehicle, and to generate a second control command based on the first control command for controlling at least one component of the vehicle; and a second vehicle interface module configured to receive the first control command from the autonomous driving system in parallel with the first vehicle interface module, and to replace the first vehicle interface module in generating the second control command based on the first control command in response to an anomaly in the first vehicle interface module.

[0021] In this way, the embodiments of this disclosure can perform hot backup of command data based on a pair of vehicle interface modules, and can use a second vehicle module to replace the first vehicle interface module to complete the generation of control commands when the first vehicle interface module malfunctions, thereby improving vehicle safety.

[0022] The following section provides a detailed description of various example implementations of this scheme, with reference to the accompanying drawings.

[0023] Referring first to Figure 1, which schematically illustrates an example environment 100 in which embodiments of the present disclosure may be implemented.

[0024] As shown in Figure 1, environment 100 may include vehicle 110. Vehicle 110 may have vehicle interface system 120, autonomous driving system 130, and basic vehicle equipment system 140. Vehicle 110 may provide vehicle interface system 120, autonomous driving system 130, and basic vehicle equipment system 140 based on local devices configured within the vehicle body.

[0025] The autonomous driving system 130 can utilize configured sensors, such as cameras and radar, to acquire sensory information about the physical environment in which the vehicle 110 is located. The autonomous driving system 130 can generate a first control command based on the sensory information. Further, the vehicle interface system 120 can receive the first control command from the autonomous driving system 130 and generate a second control command based on the first control command for controlling at least one component of the vehicle 110. The vehicle interface system 120 can also provide the generated second control command to the base vehicle equipment system 140. The base vehicle equipment system 140 can, based on the received second control command, cause the vehicle 110 to perform an operation corresponding to the second control command.

[0026] The following will detail the specific implementation of the vehicle interface system 120, the autonomous driving system 130, and the basic vehicle equipment system 140.

[0027] Figure 2 illustrates a schematic diagram of an example framework 200 of a system for a vehicle 110 according to some embodiments of the present disclosure. As shown in Figure 2, the system for the vehicle 110 may include a vehicle interface system 120, an autonomous driving system 130, and a base vehicle equipment system 140.

[0028] In some embodiments, the autonomous driving system 130 may be associated with a set of sensors to acquire sensor data. Furthermore, the autonomous driving system 130 may also be associated with map data and vehicle location data. Accordingly, the autonomous driving system 130 can acquire information about the current physical environment of the vehicle 110 (e.g., obstacle information, lane line information, etc.) based on the sensor data, map data, and vehicle 110 location data.

[0029] In some embodiments, the autonomous driving system 130 may generate a first control command for instructing the vehicle 110 to move, based on information about the current physical environment in which the vehicle 110 is located. For example, the first control command may be associated with a planned driving route and / or the driving speed of the vehicle 110. For example, the first control command may be used to instruct the movement of at least one component of the vehicle 110. For example, the at least one component may include a component indicated or included by the base vehicle equipment system 140.

[0030] In some embodiments, the base vehicle equipment system 140 may include, for example, the body domain of the vehicle 110. As an example, the body domain may refer to the roof portion, door portion, window portion, side portion, roof pillar portion, front and rear bumper portion, chassis portion, etc. of the vehicle 110.

[0031] In some embodiments, the base vehicle equipment system 140 may include, for example, a vehicle cabin area. As an example, the cabin area may refer to the interior areas of the vehicle 110. Examples include, for instance, the instrument panel, seats, storage spaces, air conditioning, infotainment (e.g., central control screen, navigation, audio controls), safety features (e.g., seat belts, airbags, etc.), lighting (e.g., interior lights, reading lights, ambient lighting, etc.), multimedia interfaces (e.g., USB interface, SD card slot), and so on.

[0032] In some embodiments, the base vehicle equipment system 140 may include, for example, the braking system, steering system, drive system, etc. of the vehicle 110.

[0033] As an example, during the development of vehicle 110, to improve development efficiency, the autonomous driving system 130 and the base vehicle equipment system 140 can be developed independently. Due to the relative independence of the development process, the autonomous driving system 130 and the base vehicle equipment system 140 may be configured with different communication protocols for sending and receiving data. The communication signal definitions, interface naming rules, and / or calling methods of various components in the autonomous driving system 130 or the base vehicle equipment system 140 may also differ. Therefore, it is necessary to convert the instructions or data issued by the autonomous driving system 130 (or the base vehicle equipment system 140) according to the predetermined protocol and / or preset rules associated with the base vehicle equipment system 140 (or the autonomous driving system 130) so that the base vehicle equipment system 140 (or the autonomous driving system 130) can understand the received instructions or data.

[0034] In some embodiments, continuing to refer to FIG2, this disclosure provides a vehicle interface system 120. The vehicle interface system 120 can be used to realize data conversion and transmission between the autonomous driving system 130 and the base vehicle equipment system 140. In this way, the vehicle interface system 120 can meet the data transmission (e.g., instruction transmission, transmission of execution status of instructions, etc.) between different types of autonomous driving systems 130 and base vehicle equipment systems 130.

[0035] As shown in Figure 2, the vehicle interface system 120 of this disclosure may include two vehicle interface modules (VIMs). A vehicle interface module, or VIM, refers to a communication and function control module that connects the L4 autonomous driving system platform and the vehicle platform. The VIM can perform functions such as communication protocol conversion, power supply and status management of the autonomous driving system, and monitoring of failures in the autonomous driving system and vehicle status functions. It should be understood that although the vehicle interface system 120 includes two vehicle interface modules in the embodiment shown in Figure 2, this is merely exemplary and not limiting; in embodiments according to this disclosure, the number of vehicle interface modules may be greater than this number.

[0036] In some embodiments, as shown in FIG2, the vehicle interface system 120 may include a first vehicle interface module 145-1 and a second vehicle interface module 145-2.

[0037] In some embodiments, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 are configured with identical hardware resources. Thus, by setting up a redundant vehicle interface module (the second vehicle interface module 145-2) with completely identical hardware resources, the redundant vehicle interface module can replace the primary vehicle interface module (e.g., the first vehicle interface module 145-1) to perform all functions such as sending and receiving data and processing data when the primary vehicle interface module malfunctions. In this way, this disclosure avoids safety issues in the vehicle 110 due to the lack of a redundant vehicle interface module or functional degradation due to incomplete hardware resources in the redundant vehicle interface module when the primary vehicle interface module malfunctions, thereby satisfying the safety and reliability requirements of autonomous driving and improving the user experience.

[0038] As an example, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can be configured with the same main control chip. As an example, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can be configured with the same peripheral resources. As an example, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can be configured with the same communication interface.

[0039] For example, the communication interface may be associated with at least one of a Controller Area Network (CAN), an Analog-to-Digital (A / D) converter, a High Speed ​​Data (HSD) converter, a General-Purpose Input / Output (GPIO) port, an Electrically Erasable Programmable Read-Only Memory (EFPROM), a Not-OR Flash (NOR Flash) device, an Embedded MultiMediaCard (EMMC), a Double Data Rate (DDR) synchronous dynamic random access memory, a Power Management IC (PMIC), and an Ethernet network. As an example, the data transmission processes of the various lines between the autonomous driving system 130, the vehicle interface system 120, and the base vehicle equipment system 140 mentioned in this disclosure can all refer to the communication interfaces mentioned herein, and will not be described further hereafter. It is worth noting that this disclosure is not intended to limit the communication protocols or communication interfaces used in the data transmission process.

[0040] In some embodiments, the first vehicle interface module 145-1 may be primarily utilized, or in general, for receiving, converting, and / or transmitting data.

[0041] In some embodiments, the first vehicle interface module 145-1 is configured to receive a first control command from the autonomous driving system 130 of the vehicle 110. As an example, the first control command may instruct a class of commands from the autonomous driving system 130. For instance, the first control command may include a steering command for the steering system of the vehicle 110. Further, the first vehicle interface module 145-1 may generate a second control command based on the first control command for controlling at least one component of the vehicle 110 (e.g., the steering system). As an example, the first control command may be associated with, for example, the communication protocol and / or preset rules of the autonomous driving system 130. The second control command generated by the first vehicle interface module 145-1 may be associated with the communication protocol and / or preset interface rules of at least one component of the vehicle 110. As an example, the first vehicle interface module 145-1 may generate a second control command based on the first control command from the autonomous driving system 130 that can control the movement of at least one component of the vehicle 110.

[0042] Referring again to Figure 2, in some embodiments, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can be connected via line 170 to achieve bidirectional data transmission. As an example, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can transmit data bidirectionally based on CAN or Ethernet protocols.

[0043] The second vehicle interface module 145-2 can determine whether the first vehicle interface module 145-1 is malfunctioning in a variety of ways. In some embodiments, the second vehicle interface module 145-2 can monitor the heartbeat signal of the first vehicle interface module 145-1 based on line 170. As an example, the second vehicle interface module 145-2 can determine that the first vehicle interface module 145-1 is malfunctioning in response to the inability to detect a heartbeat signal within a predetermined period of time (e.g., within 10 milliseconds).

[0044] As an alternative, in some embodiments, the second vehicle interface module 145-2 may determine that the first vehicle interface module 145-1 has malfunctioned if it does not receive a message from the first vehicle interface module 145-1 within a predetermined period of time (e.g., within 10 milliseconds).

[0045] In the event of a malfunction in the first vehicle interface module 145-1, the second vehicle interface module 145-2 can replace the first vehicle interface module 145-1 to generate a third control command based on the first control command of the autonomous driving system 130. The third control command has the same content as the second control command.

[0046] If the first vehicle interface module 145-1 of the vehicle interface system 120 does not malfunction, it can operate normally or be in normal operating mode, and can generate instructions corresponding to the first control command (also known as the second control command). If the first vehicle interface module 145-1 malfunctions, the second vehicle interface module 145-2 of the vehicle interface system 120 can replace the first vehicle interface module 145-1 to generate instructions corresponding to the first control command (also known as the third control command). In this case, for the first control command from the autonomous driving system 130, the component of the vehicle is provided with a third control command generated by the second vehicle interface module 145-2, instead of the second control command generated by the first vehicle interface module 145-1. The control effect of this third control command on at least one component of the vehicle 110 is the same as that of the second control command.

[0047] In some embodiments, the second vehicle interface module 145-2 may, in response to an anomaly in the first vehicle interface module, acquire a first message count value associated with the first vehicle interface module 145-1. Further, the second vehicle interface module 145-2 may determine a message count value associated with data transmitted by the second vehicle interface module 145-2 based on the first message count value. As an example, the first message count value may, for instance, indicate the number or sequence in which the first vehicle interface module sends instructions to the base vehicle equipment system 140.

[0048] As an example, the first message count value may include, for instance, the message count value associated with the first vehicle interface module sending a control command (e.g., a second control command or the most recently sent control command). Further, the second vehicle interface module 145-2 may determine a second message count value for sending a third control command based on the first message count value. The second vehicle interface module 145-2 may send a second control command associated with the second message count value. For example, the second vehicle interface module 145-2 may send a second control command associated with the second message count value to at least one component of the base vehicle equipment system 140 or the vehicle 110. Thus, embodiments of this disclosure can ensure that when the first vehicle interface module 145-1 malfunctions, the second message count value received by the base vehicle equipment system 140 or the autonomous driving system 130 from the second vehicle interface module can continuously change relative to the first message count value, preventing the base vehicle equipment system 140 or the autonomous driving system 130 from triggering the generation of communication anomaly information.

[0049] Referring again to Figure 2, in some embodiments, the first vehicle interface module 145-1 can communicate with the autonomous driving system 130 via a first master line 150-1 and a first slave line 150-2. As an example, the first master line 150-1 and the first slave line 150-2 correspond to the same communication protocol or communication interface.

[0050] In some embodiments, the second vehicle interface module 145-2 is configured to receive a first control command from the autonomous driving system in parallel with the first vehicle interface module 145-1.

[0051] For example, the second vehicle interface module 145-2 can verify the instructions (or data) received by the first vehicle interface module 145-1 from the autonomous driving system 130 based on the received instructions (or data) from the autonomous driving system 130. Exemplarily, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can each generate a verification value (e.g., calculate the sum of each byte in the data) based on the received instructions from the autonomous driving system 130, and complete the data verification based on the two verification values. For example, if the two verification values ​​are the same, it can be determined that there is no problem with the data transmission process; if the two verification values ​​are different, it indicates that there is a problem with the data transmission process. This disclosure is not intended to limit the specific method for generating verification values, but rather to provide an example of how to generate them.

[0052] In some embodiments, the second vehicle interface module 145-2 can communicate with the autonomous driving system 130 via the second master line 155-1 and the second slave line 155-2. As an example, the second master line 155-1 and the second slave line 155-2 correspond to the same communication protocol or communication interface.

[0053] Each master line and slave line can follow different communication protocols or communication interfaces. In some embodiments, the first master line 150-1 and the second master line 155-1 can correspond to the same communication protocol or communication interface. Furthermore, in some embodiments, the first slave line 150-2 and the second slave line 155-2 can correspond to the same communication protocol or communication interface.

[0054] In some embodiments, continuing to refer to FIG2, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can be connected for communication via line 170 to achieve bidirectional data transmission. As an example, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 can perform bidirectional data transmission based on CAN or Ethernet protocols.

[0055] In some embodiments, the first vehicle interface module 145-1 may, in response to the absence of an anomaly in the first main line 150-1 (e.g., based on data received from the first main line 150-1), acquire a first instruction from the autonomous driving system 130 based on the first main line 150-1. Further, the first vehicle interface module 145-1 may determine a first control instruction from the autonomous driving system 130 based on the first instruction. As an example, the first vehicle interface module 145-1 may directly use the first instruction as the first control instruction. As an example, the first instruction may include data associated with the first control instruction, and the first vehicle interface module 145-1 may determine the first control instruction based on the data associated with the first control instruction.

[0056] If no anomaly occurs on the first main line 150-1, the first vehicle interface module 145-1 can receive a first instruction from the autonomous driving system 130 based on the first slave line 150-2. As an example, the first vehicle interface module 145-1 can use the first instruction obtained based on the first slave line 150-2 as a first backup instruction. This first backup instruction can serve as a backup, for example, it can be used to determine a first control instruction in the event of an anomaly on the first main line 150-1. It is understood that the instructions or data received by the first vehicle interface module 145-1 from the autonomous driving system 130 based on the first main line 150-1 and the first slave line 150-2 are the same.

[0057] There are multiple ways to determine whether an anomaly has occurred in the main line 150-1. In some embodiments, the first vehicle interface module 145-1 may determine that an anomaly has occurred in the first main line 150-1 in response to not receiving an instruction from the autonomous driving system 130 from the first main line 150-1, and based on the instruction received by the second vehicle interface module 145-2 from the autonomous driving system 130 based on the second main line 155-1 from the second main line 170.

[0058] As an alternative, in some embodiments, continuing to refer to FIG2, the first vehicle interface module 145-1 may determine that an anomaly has occurred in the first main line 150-1 in response to not receiving an instruction from the autonomous driving system 130 from the first main line 150-1, and based on the instruction received from the autonomous driving system 130 from the first secondary line 150-2.

[0059] In some alternatives, the first vehicle interface module 145-1 may determine that the first slave line 150-2 has malfunctioned in response to not receiving instructions from the autonomous driving system 130 from the first slave line 150-2 and based on the instructions received from the autonomous driving system 130 from the first master line 150-1.

[0060] In the event of an anomaly in the first main line 150-1, for example, the first vehicle interface module 145-1 may determine a first control command based on a first backup command. Alternatively, the first vehicle interface module 145-1 may, in response to an anomaly in the first main line 150-1, send the anomaly information of the first main line 150-1 to the second vehicle interface module 145-2 based on line 170.

[0061] Referring again to Figure 2, while the first vehicle interface module 145-1 determines the first control command, the second vehicle interface module 145-2 can also perform a similar operation. Specifically, the second vehicle interface module 145-2 can receive a second command from the autonomous driving system 130 based on the second main line 155-1 to determine the first control command. By obtaining the first control command, the second vehicle interface module 145-2 can, in the event of an anomaly in the first vehicle interface module 145-1, replace the first vehicle interface module 145-1 in generating corresponding control commands for controlling vehicle components based on the first control command.

[0062] In some embodiments, the second vehicle interface module 145-2 may send a second instruction to the first vehicle interface module 145-1 in response to an anomaly in the first main line 150-1 of the first vehicle interface module, so that the first vehicle interface module 145-1 determines a first control instruction based on the second instruction. In this way, the second vehicle interface module 145-2 can provide signal support for the first vehicle interface module 145-1, making the vehicle interface system 120 more robust.

[0063] Furthermore, in some embodiments, the second vehicle interface module 145-2 may receive a second instruction from the autonomous driving system via the second slave line 155-2 as a second backup instruction. It is understood that the instructions or data received by the second vehicle interface module 145-2 from the autonomous driving system 130 via the second master line 155-1 and the second slave line 155-2 are the same.

[0064] In some cases, if an anomaly occurs on the second main line, the second vehicle interface module 145-2 can determine the first control command based on the second backup command.

[0065] Whether an anomaly has occurred on the second main line can be determined in several ways. As an example, the second vehicle interface module 145-2 can determine that an anomaly has occurred on the second main line 155-1 if it does not receive instructions from the autonomous driving system 130 from the second main line 155-1, and based on the instructions received by the first vehicle interface module 145-1 from the autonomous driving system 130 based on the first main line 155-1 from line 170.

[0066] As an alternative, in some embodiments, the second vehicle interface module 145-2 may determine that an anomaly has occurred in the second main line 155-1 in response to not receiving instructions from the autonomous driving system 130 from the second main line 155-1, and based on the instructions received from the autonomous driving system 130 from the second slave line 155-2.

[0067] In some alternatives, the second vehicle interface module 145-2 may determine that the second slave line 155-2 has malfunctioned in response to not receiving instructions from the autonomous driving system 130 from the second slave line 155-2 and based on the instructions received from the autonomous driving system 130 from the second master line 155-1.

[0068] In addition to the situations discussed above, in some embodiments, the first slave line 150-2 may also malfunction. For example, if the first vehicle interface module 145-1 does not receive instructions from the autonomous driving system 130 through the first slave line 150-2, but receives instructions from the autonomous driving system 130 obtained by the second vehicle interface module 145-2 based on the second slave line 155-2 through line 170, it can be determined that the first slave line 150-2 has malfunctioned.

[0069] In the event of an anomaly in the first slave line 150-2 of the first vehicle interface module 145-1, the second vehicle interface module 145-2 may send a second backup instruction to the first vehicle interface module 145-1, so that the first vehicle interface module 145-1 may determine the first backup instruction associated with the first slave line 150-2 based on the second backup instruction.

[0070] In the event of any abnormality in any component or related wiring of the first vehicle interface module 145-1, the second vehicle interface module 145-2 may, for example, send a switching signal to the autonomous driving system 130 and / or the base vehicle equipment system 140 when it is determined that the first vehicle interface module 145-1 is unable to provide normal service, to indicate that the second vehicle interface module 145-2 will replace the first vehicle interface module 145-1 to provide the corresponding service.

[0071] In some embodiments, the first vehicle interface module 145-1 may, in response to a first anomaly occurring in the first vehicle interface module 145-1 (e.g., an anomaly occurring in the first main line 150-1 or the first slave line 150-2), send a first anomaly information associated with the first anomaly to at least one component of the vehicle 110 (e.g., a display in the cockpit domain) to alert maintenance personnel for inspection and repair.

[0072] Additionally or alternatively, in some embodiments, the second vehicle interface module 145-2 may, in response to a second anomaly occurring in the second vehicle interface module 145-2 (e.g., an anomaly occurring in the second master line 155-1 or the second slave line 155-2), send a second anomaly information associated with the second anomaly to at least one component of the vehicle 110 (e.g., a display in the cockpit domain) to alert maintenance personnel for inspection and repair.

[0073] In some embodiments, the first vehicle interface module 145-1 is configured to receive first execution data from at least one component of the vehicle 110 (e.g., at least one component associated with the base vehicle equipment system 140). As an example, the first execution data may indicate execution information of at least one component in response to a second control command. For instance, if the second control command can be used to control the steering system to perform steering, the first execution data may indicate the steering system's steering action in response to the second control command.

[0074] Based on the first execution data, the first vehicle interface module 145-1 can generate second execution data for provision to the autonomous driving system 130. As an example, the first vehicle interface module 145-2 can generate second execution data based on the first execution data and communication protocols or preset rules (e.g., communication signal definitions, communication interface call rules, etc.) associated with the autonomous driving system 130. In this way, the execution status (or execution information) of at least one component in response to the first control command can be fed back to the autonomous driving system 130, enabling the autonomous driving system 130 to adjust or determine new control commands based on the execution status.

[0075] In some cases, the second vehicle interface module 145-2 can receive first execution data from at least one component in parallel with the first vehicle interface module 145-1. Further, the second vehicle interface module 145-2 can, in response to an exception in the first vehicle interface module 145-1, replace the first vehicle interface module 145-1 in generating third execution data based on the first execution data. The third execution data has the same content as the second execution data. As an example, for the first execution data from at least one component, the execution information of the at least one component associated with the second and third execution data is the same.

[0076] In some embodiments, continuing to refer to FIG2, the first vehicle interface module 145-1 can communicate with the base vehicle equipment system 140 based on the third master line 160-1 and the third slave line 160-2. As an example, the third master line 160-1 and the third slave line 160-2 correspond to the same communication protocol or communication interface.

[0077] Similarly, the second vehicle interface module 145-2 can communicate with the base vehicle equipment system 140 via the fourth master line 165-1 and the fourth slave line 165-2. As an example, the fourth master line 165-1 and the fourth slave line 165-2 correspond to the same communication protocol or communication interface.

[0078] As an example, the determination of whether the third main line 160-1, the third slave line 160-2, the fourth main line 165-1 and / or the fourth slave line 165-2 have an anomaly can refer to the above description of the anomaly of the first main line 150-1, the first slave line 150-2, the second main line 155-1 and / or the second slave line 155-2, which will not be repeated here.

[0079] In some embodiments, to ensure stable operation, when the vehicle interface system 120 starts, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 will perform startup detection to determine the master vehicle interface module and the slave vehicle interface module. As an example, the master vehicle interface module can be used to receive data (or instructions) and send data. For example, the master vehicle interface module can at least receive data from the autonomous driving system 130 and at least send data to the base vehicle equipment system 140. The slave vehicle interface module can be used to receive data without sending data. For example, the slave vehicle interface module can at least receive data from the autonomous driving system 130 and / or data from the base vehicle equipment system 140.

[0080] As an example, the slave vehicle interface module can respond to an exception in the master vehicle interface module and take over the function of sending data to the outside world.

[0081] Alternatively, the first vehicle interface module 145-1 may, in response to being activated, determine whether a first indication signal has been received from the second vehicle interface module 145-2 within a first preset time period. As an example, the first indication signal may be a preset signal issued by the second vehicle interface module 145-2, or it may be a configuration of a preset output interface by the second vehicle interface module 145-2 (e.g., setting a GPIO interface associated with the second vehicle interface module 145-2 to a high level).

[0082] Additionally or alternatively, the first vehicle interface module 145-1 may determine that the second control command was generated by the first vehicle interface module 145-1 in response to not receiving the first indication signal within a first preset time period (e.g., 10 milliseconds). As an example, the first vehicle interface module 145-1 may determine that the first vehicle interface module 145-1 is the master vehicle interface module and the second vehicle interface module 145-2 is the slave vehicle interface module in response to not receiving the first indication signal within the first preset time period.

[0083] In some embodiments, the first vehicle interface module 145-1 may determine that the second vehicle interface module 145-2 is the master vehicle interface module and the first vehicle interface module 145-2 is the slave vehicle interface module in response to receiving a first indication signal within a first preset time period and receiving a first heartbeat signal from the second vehicle interface module 145-2 within a second preset time period (e.g., 10 milliseconds).

[0084] In some embodiments, the second vehicle interface module 145-2 may, in response to the activation of the second vehicle interface module, determine whether a second indication signal is received from the first vehicle interface module 145-1 within a third preset time period (e.g., 100 milliseconds). As an example, the second indication signal may be a preset signal issued by the first vehicle interface module 145-1, or it may be a configuration of a preset output interface by the first vehicle interface module 145-1 (e.g., setting a GPIO interface associated with the first vehicle interface module 145-1 to a high level). As an example, the specific duration of the third preset time period may be determined based on the activation time of the first vehicle interface module 145-1.

[0085] For example, the second vehicle interface module 145-2 may determine that the first vehicle interface module 145-1 is the master vehicle interface module and the second vehicle interface module 145-2 is the slave vehicle interface module in response to receiving a second indication signal within a third preset time period and receiving a second heartbeat signal (e.g., a heartbeat message generated by the second vehicle interface module 145-2) from the first vehicle interface module 145-1 within a fourth preset time period (e.g., 10 milliseconds).

[0086] Alternatively, the second vehicle interface module 145-2 may determine that the second vehicle interface module 145-2 is the master vehicle interface module and the first vehicle interface module 145-1 is the slave vehicle interface module in response to not receiving the second indication signal within a third preset time period.

[0087] Additionally or alternatively, the second vehicle interface module 145-2 may provide the first vehicle interface module 145-1 with a first heartbeat signal (e.g., sending a heartbeat message associated with the second vehicle interface module 145-2) and a first indication signal (e.g., setting the GPIO interface associated with the second vehicle interface module 145-2 to a high level) in response to not receiving the second indication signal within a third preset time period.

[0088] In this way, the embodiments of this disclosure can quickly determine the master vehicle interface module and the slave vehicle interface module when the vehicle interface system starts up, thereby ensuring the stable operation of the vehicle interface system and improving the safety and reliability of the vehicle.

[0089] Figure 3 shows a schematic diagram of an example frame 300 of a first vehicle interface module 145-1 according to some embodiments of the present disclosure. As an example, the first vehicle interface module 145-1 and the second vehicle interface module 145-2 are configured with identical hardware resources; the first vehicle interface module 145-1 is described here as an example. It should be understood that the description of the first vehicle interface module 145-1 in conjunction with Figure 3 also applies to the second vehicle interface module 145-2.

[0090] As shown in Figure 3, the first vehicle interface module 145-1 may include a traditional gateway module 175, a vehicle control interface module 180, and a backup system arbitration module 185.

[0091] In some embodiments, as shown in FIG3, the first vehicle interface module 145-1 may include a conventional gateway module 175. The first vehicle interface module 145-1 may provide functions such as signal routing, signal verification, signal security mechanisms (e.g., Secure Onboard Communication (SecOC)), fault diagnosis, Over-the-Air (OTA) upgrades, network management and services (e.g., Service-Oriented Architecture (SOA) services) based on the conventional gateway module 175.

[0092] In some embodiments, continuing to refer to FIG3, the first vehicle interface module 145-1 may include a vehicle control interface module 180. The first vehicle interface module 145-1 provides, for example, modes management (e.g., enabling or disabling autonomous driving functions), system power management (e.g., determining the power-on time and power-on sequence of various components in the vehicle), vehicle control signal arbitration (e.g., determining the target signal for controlling the vehicle 110 from among multiple vehicle control signals received), calibration parameter threshold limitation (e.g., limiting the generation of control commands to ensure that the motion parameters of at least one component of the vehicle 110 indicated by the control command are relatively stable), button detection (e.g., button detection associated with the start / stop of the air conditioner), function failure monitoring, data logging, and other functions based on the vehicle control interface module.

[0093] In some embodiments, continuing to refer to FIG3, the first vehicle interface module 145-1 may include a backup system arbitration module 185. As an example, for the safety and reliability of vehicle 110, at least two backup systems are typically installed in vehicle 110 so that necessary functions can be performed based on the backup systems after the main system of the vehicle malfunctions. As an example, the first vehicle interface module 145-1 may, in response to receiving multiple control commands from multiple backup systems, determine a target control command from the multiple control commands, and complete the control of vehicle 110 based on the target control command. As an example, the control commands of the backup systems may include, for example, stopping at a lane, emergency stopping, and data forwarding.

[0094] Based on the vehicle interface system described above, embodiments of this disclosure can provide a pair of vehicle interface modules configured with identical hardware resources, thereby maintaining existing autonomous driving functions and ensuring no functional degradation even if one vehicle interface module malfunctions. Thus, embodiments of this disclosure can improve the safety and reliability of autonomous driving and enhance the user experience.

[0095] Figure 4 shows a block diagram of an electronic device 400 in which one or more embodiments of the present disclosure may be implemented. It should be understood that the electronic device 400 shown in Figure 4 is merely exemplary and should not constitute any limitation on the functionality and scope of the embodiments described herein. The electronic device 400 may be used to implement at least one of the vehicle interface system 120, vehicle interface module 145-1, and second vehicle interface module 145-2 described above in conjunction with Figures 1 to 3.

[0096] As shown in Figure 4, electronic device 400 is in the form of a general-purpose electronic device. Components of electronic device 400 may include, but are not limited to, one or more processors or processing units 410, memory 420, storage device 430, one or more communication units 440, one or more input devices 450, and one or more output devices 460. Processing unit 410 may be a physical or virtual processor and is capable of performing various processes according to programs stored in memory 420. In a multiprocessor system, multiple processing units execute computer-executable instructions in parallel to improve the parallel processing capability of electronic device 400.

[0097] Electronic device 400 typically includes multiple computer storage media. Such media can be any available media accessible to electronic device 400, including but not limited to volatile and non-volatile media, removable and non-removable media. Memory 420 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. Storage device 430 can be a removable or non-removable medium and can include machine-readable media, such as flash drives, disks, or any other media that can be used to store information and / or data (e.g., training data for training) and can be accessed within electronic device 400.

[0098] Electronic device 400 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not shown in FIG. 4, disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks may be provided. In these cases, each drive may be connected to a bus (not shown) via one or more data media interfaces. Memory 420 may include computer program product 425 having one or more program modules configured to perform various methods or actions of various embodiments of the present disclosure.

[0099] Communication unit 440 enables communication with other electronic devices via a communication medium. Additionally, the functionality of components of electronic device 400 can be implemented using a single computing cluster or multiple computing machines capable of communicating via communication connections. Therefore, electronic device 400 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network node.

[0100] Input device 450 can be one or more input devices, such as a mouse, keyboard, trackball, etc. Output device 450 can be one or more output devices, such as a monitor, speaker, printer, etc. Electronic device 400 can also communicate with one or more external devices (not shown) via communication unit 440 as needed. These external devices include storage devices, display devices, etc., and can communicate with one or more devices that enable user interaction with electronic device 400, or with any device that enables electronic device 400 to communicate with one or more other electronic devices (e.g., network card, modem, etc.). Such communication can be performed via input / output (I / O) interface (not shown).

[0101] According to an exemplary implementation of this disclosure, a computer-readable storage medium is provided that stores one or more computer instructions, wherein one or more computer instructions are executed by a processor to implement the methods described above.

[0102] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products implemented according to this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0103] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processing unit of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0104] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions that execute on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0105] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0106] Various implementations of this disclosure have been described above. The foregoing description is exemplary and not exhaustive, nor is it limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is chosen to best explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the implementations disclosed herein.

Claims

1. A vehicle interface system, comprising: The first vehicle interface module is configured to receive a first control command from the vehicle's autonomous driving system, and to generate a second control command based on the first control command for controlling at least one component of the vehicle. as well as The second vehicle interface module is configured to receive the first control command from the autonomous driving system in parallel with the first vehicle interface module, and to generate a third control command based on the first control command in response to an anomaly occurring in the first vehicle interface module, wherein the third control command has the same content as the second control command.

2. The vehicle interface system according to claim 1, wherein the second vehicle interface module is further configured to: In response to an abnormality in the first vehicle interface module, the first message count value associated with the first vehicle interface module is obtained; Based on the first message count value, determine the second message count value used by the second vehicle interface module to send the third control command; and The second control command is sent in association with the second message count value.

3. The vehicle interface system according to claim 1, wherein the first vehicle interface module is further configured to: In response to the absence of an anomaly on the first main line, the system receives a first instruction from the autonomous driving system based on the first main line to determine the first control instruction, and receives the first instruction from the autonomous driving system based on the first slave line as a first backup instruction; and In response to an anomaly occurring on the first main line, the first control command is determined based on the first backup command.

4. The vehicle interface system according to claim 3, wherein the first vehicle interface module is further configured to: in response to an anomaly occurring in the first main line, send the anomaly information of the first main line to the second vehicle interface module.

5. The vehicle interface system according to claim 1, wherein the second vehicle interface module is further configured to: Based on receiving a second instruction from the autonomous driving system via the second main line, the first control instruction is determined; and In response to an anomaly occurring on the first main line of the first vehicle interface module, the second instruction is sent to the first vehicle interface module so that the first vehicle interface module can determine the first control instruction based on the second instruction.

6. The vehicle interface system according to claim 5, wherein the second vehicle interface module is further configured to: Based on receiving the second instruction from the autonomous driving system via the second slave line as a second backup instruction; and In response to an anomaly occurring on the first slave line of the first vehicle interface module, the second backup instruction is sent to the first vehicle interface module, so that the first vehicle interface module determines the first backup instruction associated with the first slave line based on the second backup instruction.

7. The vehicle interface system according to claim 1, wherein the first vehicle interface module is further configured to: in response to a first abnormality occurring in the first vehicle interface module, send first abnormality information associated with the first abnormality to at least one component of the vehicle.

8. The vehicle interface system according to claim 1, wherein the second vehicle interface module is further configured to: In response to a second anomaly occurring in the second vehicle interface module, a second anomaly information associated with the second anomaly is sent to at least one component of the vehicle; and / or Monitor the heartbeat signal of the first vehicle interface module; and determine that the first vehicle interface module is malfunctioning if the heartbeat signal cannot be detected within a predetermined time period.

9. The vehicle interface system according to claim 1, wherein the first vehicle interface module is further configured to: In response to the activation of the first vehicle interface module, determine whether a first indication signal from the second vehicle interface module is received within a first preset time period; In response to the fact that the first indication signal is not received within the first preset time period, the first vehicle interface module is determined to be the main vehicle interface module. as well as In response to receiving the first indication signal within the first preset time period and receiving the first heartbeat signal from the second vehicle interface module within the second preset time period, the second vehicle interface module is determined to be the master vehicle interface module and the first vehicle interface module is the slave vehicle interface module.

10. The vehicle interface system according to claim 1, wherein the second vehicle interface module is further configured to: In response to the activation of the second vehicle interface module, it is determined whether a second indication signal from the first vehicle interface module is received within a third preset time period; as well as In response to receiving the second indication signal within a third preset time period and receiving the second heartbeat signal from the first vehicle interface module within a fourth preset time period, the first vehicle interface module is determined to be the main vehicle interface module. as well as In response to the fact that the second indication signal is not received within the third preset time period, the second vehicle interface module is determined to be the master vehicle interface module, and the first vehicle interface module is the slave vehicle interface module.

11. The vehicle interface system according to claim 10, wherein the second vehicle interface module is further configured to: In response to the failure to receive the second indication signal within the third preset time period, a first heartbeat signal and a first indication signal are provided to the first vehicle interface module.

12. The vehicle interface system according to claim 1, wherein the second vehicle interface module is further configured to: Based on the received instructions from the autonomous driving system, the instructions received by the first vehicle interface module from the autonomous driving system are verified.

13. The vehicle interface system according to claim 1, wherein: The first vehicle interface module is further configured to: receive first execution data from the at least one component, and generate second execution data based on the first execution data for providing to the autonomous driving system, wherein the first execution data is used to indicate execution information of the at least one component in response to the second control command; and / or The second vehicle interface module is further configured to: receive the first execution data from the at least one component in parallel with the first vehicle interface module, and, in response to an exception occurring in the first vehicle interface module, generate third execution data based on the first execution data, the third execution data having the same content as the second execution data, in place of the first vehicle interface module.

14. An electronic device comprising: Memory and processor; The memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the first vehicle interface module and / or the second vehicle interface module in the vehicle interface system according to any one of claims 1 to 12.

15. A computer-readable storage medium having stored thereon one or more computer instructions, wherein the one or more computer instructions are executed by a processor to implement a first vehicle interface module and / or a second vehicle interface module in a vehicle interface system according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Control system, method and device of automatic driving vehicle and automatic driving vehicle

    CN114872717A

  • Apparatus and method for controlling vehicle

    CN117585008A

  • Operating system control method and device, equipment and storage medium

    CN117585012A

  • Vehicle automatic driving redundancy system and control method

    CN117719528A

  • Vehicle control redundancy system and control method

    CN117719529A