System safety associated with vehicle autonomous driving
By introducing intelligent power supplies and redundant SOCs into autonomous driving systems and utilizing ASIL-D safety islands and PMICs to monitor faults, the system's fault monitoring and isolation issues in high-risk environments are addressed, improving safety integrity and availability while reducing system complexity and cost.
Patent Information
- Application Number
- CN202510225419.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-03-01
- Filing Date
- 2025-02-27
- Publication Date
- 2025-09-09
AI Technical Summary
Existing technologies make it difficult to effectively monitor and isolate failures of electronic components while meeting the safety integrity and availability requirements of Level 2 and Level 3 autonomous driving systems, especially in high-risk environments at the ASIL-D level, where the system complexity and cost are high.
Adopt intelligent power supply or redundant SOC, monitor the status of ASIL-B and ASIL-D safety islands through ASIL-D safety islands and ASIL-D PMICs, implement fault detection and safety isolation, downgrade operating modes to ensure system safety, and use ASIL-D PMICs instead of or in addition to MCUs to reduce costs.
It achieves effective fault monitoring and isolation in Level 2 and Level 3 autonomous driving systems, reduces system complexity and cost, ensures the safe state of the system in the event of a fault, and meets the safety integrity requirements of ASIL-D level.
Smart Images

Figure CN120606864A_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims the benefit of U.S. Provisional Application No. 63 / 560,591, filed on March 1, 2024, entitled “SYSTEM SAFETY FOR LEVEL 2 OR LEVEL 3 AUTONOMY,” which is incorporated herein by reference in its entirety. Background Art
[0003] Automotive Safety Integrity Level (ASIL) is a risk classification system for functional safety in road vehicles, defined by the ISO 26262 standard. ASIL categorizes hazard levels into one of four levels, designated A through D, with an additional fifth level for non-hazardous systems or components. ASIL D represents the highest risk level, while ASIL A represents the lowest.
[0004] The standard defines functional safety as “the absence of unreasonable risk of hazards due to the malfunctioning behavior of electrical or electronic systems.” ASIL establishes safety requirements for ISO 26262-compliant automotive components based on the probability and acceptability of hazards.
[0005] Systems including vehicle brakes may require ASIL-D, the most stringent level applied to safety assurance, because their failure is associated with significant risk. Examples of ASIL-B are headlights and brake lights, while ASIL C can be used for systems including cruise control. Taillights are an example of lights that may be classified as ASIL-A.
[0006] Various aspects of the subject technology can help improve the overall cost, reliability, and efficiency of circuits or other electronic components. Summary of the Invention
[0007] The present description as a whole relates to a smart power supply or redundant SOC that can be implemented to meet the safety integrity and availability of a Level 2 autonomous driving system or a Level 3 autonomous driving system. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Certain features of the subject technology are set forth in the appended claims.For illustrative purposes, however, several embodiments of the subject technology are set forth in the following figures.
[0009] Figure 1 An exemplary integrated circuit associated with the safety or availability of a Level 2 autonomous vehicle is illustrated.
[0010] Figure 2An exemplary sequence diagram associated with monitoring a safety island of a system-on-chip (SOC) in a Level 2 autonomous driving system is illustrated.
[0011] Figure 3 An exemplary sequence diagram associated with a safety ASIL-D power management integrated circuit (PMIC) that monitors ASIL-D safety islands in a Level 2 automated driving system and notifies vehicle systems is illustrated.
[0012] Figure 4 An exemplary integrated circuit associated with the safety or availability of a Level 3 autonomous vehicle is illustrated.
[0013] Figure 5 An exemplary sequence diagram associated with a second SOC and a first safety island monitoring a first SOC in a Level 3 autonomous driving system is illustrated.
[0014] Figure 6 An exemplary sequence diagram associated with a second SOC in a Level 3 automated driving system and a first safety ASIL-D PMIC monitoring a first ASIL-D safety island of a first SOC is illustrated. DETAILED DESCRIPTION
[0015] The specific embodiments set forth below are intended to be used as a description of various configurations of the subject technology, and are not intended to represent the only configuration that can be put into practice. The accompanying drawings are incorporated herein and constitute a part of the specific embodiments. In order to provide a comprehensive understanding of the subject technology, the specific embodiments include specific details. However, the subject technology is not limited to the specific details set forth herein, and one or more other specific implementations can be used to put it into practice. In one or more specific implementations, well-known structures and components are shown in block diagram form to avoid confusion between the concepts of the subject technology.
[0016] The U.S. Department of Transportation has adopted six levels of driving automation, ranging from 0 (fully manual) to 5 (fully autonomous). For example, at Level 2 autonomous driving, there is an advanced driver assistance system (ADAS) that can provide continuous assistance with acceleration, braking, and steering while the driver is seated in the vehicle and can control the vehicle at all times. The driver remains engaged and focused. ASIL-rated SoCs can be used to implement this autonomous driving.
[0017] A vehicle performing Level 3 autonomous driving can detect its environment and make intelligent decisions, such as accelerating to pass a slow-moving vehicle. Level 3 systems proactively perform driving tasks while the driver can still take over. If the system becomes inoperable and notifies the driver, the driver should be able to resume driving.
[0018] An ASIL rated SoC typically has several safety-critical use cases required to meet different levels of safety integrity. Due to the different coverage and residual failure rates of different ASIL levels, it is important to note that these requirements are met by planned mitigations for any interference between ASIL domains. In order to address the monitoring needs of vehicle systems (e.g., one or more electronic components), safety goals can be achieved through various levels of ASIL decomposition. When performing these decompositions, safety isolation can be planned at the intersection of the boundaries of the electrical paths, data paths, or control paths of the vehicle system, which can allow safe detection of failures (e.g., errors) of electronic components.
[0019] Isolation can ensure the availability of higher-integrity functions in the event of a fault detected in a lower-integrity function. Implementing this isolation capability can opportunistically address availability requirements in Level 2 autonomous driving systems, as failover is returned to the drive in such systems. As discussed in more detail in this article, an intelligent power supply (rather than a high-integrity microcontroller) can be implemented to meet the safety integrity and availability of Level 2 autonomous driving systems at a potentially lower cost point.
[0020] Figure 1 An exemplary integrated circuit associated with the safety or availability of a Level 2 autonomous vehicle is illustrated. With respect to Level 2 autonomous driving, a system 100 may include a system on a chip (SOC) 101. The SOC 101 may include an ASIL-B domain 102 (e.g., a power domain) or an ASIL-D safety island 103. The ASIL-B domain 102 may include safety mechanisms that achieve ASIL-B integrity across safety-critical use cases that utilize different subsystems in the ASIL-B domain 102. The ASIL-B domain 102 may be communicatively connected to one or more ASIL-B power management integrated circuits (PMICs) 105, ASIL-D safety islands 103, or ASIL-D PMICs 104. The ASIL-B PMIC 105 may include safety mechanisms that achieve ASIL-B integrity across safety-critical voltage rails that power an ASIL-B SoC domain (e.g., ASIL-B domain 102).
[0021] Continue to refer Figure 1, the ASIL-D safety island 103 may include a processor with hardware features, such as error correction code (ECC) and a programmable watchdog timer, to detect system faults or runtime faults. The processor may include a lockstep interface that is used by the integrated safety monitor to compare outputs and detect whether a fault has occurred. The ASIL-D safety island 103 may include safety mechanisms that achieve ASIL-D integrity across safety-critical use cases that use different subsystems in the domain. In addition, the safety mechanisms of the ASIL-D safety island 103 may monitor ASIL-B domains (e.g., ASIL-B domain 102) to achieve a higher level of integrity through ASIL decomposition.
[0022] The ASIL-D PMIC 104 may include safety mechanisms that achieve ASIL-D integrity across the safety-critical voltage rails that power the ASIL-D safety island 103. In addition, the safety mechanisms of the ASIL-D PMIC 104 may monitor the ASIL-D safety island 103 to achieve a higher level of integrity by mitigating the risk of correlated failures within the SOC 101. Instead of using a microcontroller (MCU), the ASIL-D PMIC 104 may be used to monitor the SOC 101, such as Figure 1 As shown. The SOC 101 may include an ASIL-D safety island 103 and an ASIL-B domain 102. The minimum functionality that can be provided by the MCU can be implemented by the ASIL-D PMIC 104. The use of the disclosed ASIL-D PMIC 104 is sufficient to achieve the required safety integrity. The ASIL-D PMIC 104 may include not only monitoring capabilities for the power rails, but also other monitoring capabilities, such as a watchdog timer. In an example, the SOC 101 may write to a specific register in the watchdog timer at a specific frequency (e.g., periodically 50ms) via its communication interface within the integrated circuit. While the frequency of writing to the register is maintained, the watchdog timer may reset its counter each time. When the frequency of writing to the register is not maintained, an alarm may be indicated and the ASIL-D PMIC 104 (because it controls power management) may cut off the power rail to the SOC 101, which may place the vehicle system in a safe state. And through the communication interface of the ASIL-D PMIC 104, higher-level systems can be alerted to the fault, which can eventually be displayed (e.g., a message showing that Level 2 autonomous driving has failed).
[0023] Figure 2An exemplary sequence diagram of a system 110 associated with monitoring a safety island 103 of a SOC 101 is illustrated. At steps 111 to 115, an ASIL-D safety island monitor 103a may monitor the status of one or more ASIL-B subsystems. The ASIL-B subsystems of the ASIL-B domain 102 may include one or more ASIL-B subsystems 120 for power (e.g., associated with step 111), an ASIL-B subsystem 121 for temperature (e.g., associated with step 112), an ASIL-B subsystem 122 for clock (e.g., associated with step 113), an ASIL-B subsystem 123 for a main CPU (e.g., associated with step 114), or an ASIL-B subsystem 124 for safety errors (e.g., associated with step 115), among others.
[0024] Monitoring can be based on receiving information within a specified threshold or not receiving information within a specified period. At step 116, based on the monitoring of steps 111 to 115, a fault can be determined. At step 117, for example, an alarm associated with a critical fault can be sent to the ASIL-D CPU 103b. At step 118, based on receiving the alarm, the ASIL-D CPU 103b can transmit a shutdown instruction to one or more ASIL-B subsystems of the ASIL-B domain 102, which can place the vehicle system in a safe state. It is contemplated herein that the ASIL-D safety island 103 can include an ASIL-D safety island monitor 103a or an ASIL-D CPU 103b.
[0025] Figure 3 An exemplary sequence diagram associated with a safety ASIL-D PMIC 104 monitoring an ASIL-D safety island 103 and notifying a vehicle system 140 is illustrated. At steps 131 through 135, the ASIL-D PMIC 104 (e.g., the ASIL-D safety PMIC monitor 104a) may monitor the status of one or more ASIL-D safety island 103 subsystems. The ASIL-D safety island 103 subsystems may include one or more ASIL-D subsystems 141 for power (e.g., associated with step 131), ASIL-D subsystems 142 for temperature (e.g., associated with step 132), ASIL-D subsystems 143 for a main CPU (e.g., associated with step 134), or ASIL-D subsystems 144 for safety errors (e.g., associated with step 135), among others (e.g., step 133).
[0026] Monitoring may be based on receiving information within a specified threshold or not receiving information within a specified period. At step 136, based on the monitoring of steps 131 to 135, a fault may be determined. For example, at step 137, an alarm associated with a critical fault may be sent to the ASIL-D PMIC state machine 104b. At step 138, based on receiving the alarm, the ASIL-D PMIC state machine 104b may transmit a shutdown indication to one or more components of the SOC 101, which may place the vehicle system in a safe state. At step 139, the ASIL-D PMIC state machine 104b may shut down the Level 2 autonomous driving and transmit an alarm to the driver. Imagine, Figure 2 or Figure 3 The components of the process flow may be on a single component, or may be functional components. The vehicle system 140 may include Figure 1 one or more components.
[0027] Figure 4 An exemplary integrated circuit associated with the safety or availability of an automated vehicle is illustrated. With respect to Level 3 autonomous driving, a system 150 may include a system on a chip (SOC) 151. The SOC 151 may include an ASIL-B domain 152 (e.g., a power domain) or an ASIL-D safety island 153. The ASIL-B domain 152 may include safety mechanisms that implement ASIL-B integrity across safety-critical use cases that utilize different subsystems within the ASIL-B domain 152. The ASIL-B domain 152 may be communicatively connected to one or more ASIL-B PMICs 155, ASIL-D safety islands 153, or ASIL-D PMICs 154. The ASIL-B PMIC 155 may include safety mechanisms that implement ASIL-B integrity across safety-critical voltage rails that power an ASIL-B SoC domain (e.g., ASIL-B domain 152). The SOC 151 may be communicatively connected to an SOC 161, which may be connected to the ASIL-D safety island 163 via the ASIL-D safety island 153.
[0028] Continue to refer Figure 4, the ASIL-D safety island 153 may include safety mechanisms that achieve ASIL-D integrity across safety-critical use cases that use different subsystems in the domain. The safety mechanisms of the ASIL-D safety island 153 may monitor ASIL-B domains (e.g., ASIL-B domain 102) to achieve a higher level of integrity through ASIL decomposition. In the event of an unrecoverable fault in the ASIL-D domain (e.g., ASIL-D safety island 153), an external ASIL-D domain (e.g., ASIL-D safety island 163) may monitor the ASIL-D safety island 153 and initiate a degraded operating mode in the event of a fault. Similarly, the ASIL-D domain (e.g., ASIL-D safety island 153) may also monitor external ASIL-D domains (e.g., ASIL-D safety island 163) and initiate a degraded operating mode in the event of a fault.
[0029] ASIL-D PMIC 154 may include safety mechanisms that achieve ASIL-D integrity across the safety-critical voltage rails that power ASIL-D safety island 153. Additionally, the safety mechanisms of ASIL-D PMIC 154 may monitor ASIL-D safety island 153 to achieve a higher level of integrity by mitigating the risk of correlated failures within SOC 151.
[0030] Continue to refer Figure 4 , system 150 may include a system on chip (SOC) 161. SOC 101 may include an ASIL-B domain 162 (e.g., a power domain) or an ASIL-D safety island 163. The ASIL-B domain 162 may include safety mechanisms that achieve ASIL-B integrity across safety-critical use cases that use different subsystems in the ASIL-B domain 162. The ASIL-B domain 162 may be communicatively connected to one or more ASIL-B PMICs 165, ASIL-D safety islands 163, or ASIL-D PMICs 164. The ASIL-B PMIC 165 may include safety mechanisms that achieve ASIL-B integrity across safety-critical voltage rails that power an ASIL-B SoC domain (e.g., ASIL-B domain 162). The SOC 161 may be communicatively connected to the SOC 161, which may be connected to the ASIL-D safety island 153 via the ASIL-D safety island 163.
[0031] Continue to refer Figure 4, the ASIL-D safety island 163 may include safety mechanisms that achieve ASIL-D integrity across safety-critical use cases that use different subsystems in the domain. The safety mechanisms of the ASIL-D safety island 163 may monitor ASIL-B domains (e.g., ASIL-B domain 162) to achieve a higher level of integrity through ASIL decomposition. In the event of an unrecoverable fault in the ASIL-D domain (e.g., ASIL-D safety island 163), an external ASIL-D domain (e.g., ASIL-D safety island 153) may monitor the domain and initiate a degraded operating mode in the event of a fault. Similarly, the ASIL-D domain (e.g., ASIL-D safety island 163) may also monitor an external ASIL-D domain (e.g., ASIL-D safety island 153) and initiate a degraded operating mode in the event of a fault.
[0032] ASIL-D PMIC 164 can include safety mechanisms that achieve ASIL-D integrity across the safety-critical voltage rails that power ASIL-D safety island 163. Furthermore, the safety mechanisms of ASIL-D PMIC 164 can monitor ASIL-D safety island 163 to achieve a higher level of integrity by mitigating the risk of correlated failures within SOC 161. As disclosed, when the two SOCs (SOC 151 and SOC 161) communicate with each other, they can also monitor each other. Thus, in this example, SOC 161 or ASIL-D PMIC 154 can monitor ASIL-D safety island 153, and SOC 151 or ASIL-D PMIC 164 can monitor ASIL-D safety island 163. This is particularly useful for Level 3 autonomous driving. This configuration can reduce the number of hops required to alert SOC 161 (if SOC 151 is in a fault condition) and trigger SOC 161 to implement degraded functionality. For example, instead of two hops (e.g., ASIL-D safety island 153 to ASIL-D PMIC 154 to SOC 161), there may be one hop (e.g., ASIL-D safety island 153 to SOC 161). Degraded functionality (also referred to herein as a degraded operating mode) may include downgrading from Level 3 to Level 2, performing automated driving at a specified speed for a period of time (e.g., 40 mph for 30 seconds, 75% or less of the posted speed limit for a road, etc.), relinquishing control to the driver, or stopping the vehicle.
[0033] Figure 5An exemplary sequence diagram associated with the SOC 161 and the safety island 153 monitoring the SOC 151 is illustrated. At steps 181 to 185, the ASIL-D safety island monitor 153a may monitor the status of one or more ASIL-B subsystems of the ASIL-B domain 152. The ASIL-B subsystems of the ASIL-B domain 152 may include one or more ASIL-B subsystems 170 for power (e.g., associated with step 181), an ASIL-B subsystem 171 for temperature (e.g., associated with step 182), an ASIL-B subsystem 172 for clock (e.g., associated with step 183), an ASIL-B subsystem 173 for a main CPU (e.g., associated with step 184), or an ASIL-B subsystem 174 for safety errors (e.g., associated with step 185), etc.
[0034] Monitoring can be based on receiving information within a specified threshold or not receiving information within a specified period. At step 186, based on the monitoring of steps 181 to 185, a fault can be determined. At step 187, for example, an alarm associated with a critical fault can be sent to the ASIL-D CPU 153b. At step 188, based on receiving the alarm, the ASIL-D CPU 153b can transmit a shutdown instruction to one or more ASIL-B subsystems of the ASIL-B domain 152, which can place the vehicle system in a safe state. At step 189, the ASIL-D safety island CPU 163a can monitor the ASIL-D CPU 153b (e.g., via a watchdog timer monitor). At step 190, the ASIL-D CPU 153b can transmit a fault notification (which can be based on the alarm in step 187) to the ASIL-D safety island CPU 163a. The fault notification can be sent via an error pin or serial peripheral interface (SPI) communication. At step 191, the ASIL-D safety island CPU 163a may transmit an instruction to shut down to a safe state to the SoC 151. At step 192, the ASIL-D safety island CPU 163a may transmit an instruction to switch to a degraded operating mode to the ASIL-B subsystems of the ASIL-B domain 162. It is contemplated herein that the ASIL-D safety island 153 may include an ASIL-D safety island monitor 153a or an ASIL-D CPU 153b.
[0035] Figure 6An exemplary sequence diagram associated with the SOC 161 and the safety ASIL-D PMIC 154 monitoring the ASIL-D safety island 153 of the SOC 151 is illustrated. At steps 201 to 204, the ASIL-D PMIC 154 (e.g., the ASIL-D safety PMIC monitor 154a) may monitor the status of one or more ASIL-D safety island 153 subsystems. The ASIL-D safety island 153 subsystems may include one or more ASIL-D subsystems 221 for power (e.g., associated with step 201), ASIL-D subsystems 222 for temperature (e.g., associated with step 202), ASIL-D subsystems 223 for the main CPU (e.g., associated with step 203), or ASIL-D subsystems 224 for safety errors (e.g., associated with step 204).
[0036] Monitoring may be based on receiving information within a specified threshold or not receiving information within a specified period of time. At step 205, based on the monitoring of steps 201 to 204, a fault may be determined. For example, at step 206, an alarm associated with a critical fault may be sent to the ASIL-D PMIC state machine 154b. At step 207, based on receiving the alarm, the ASIL-D PMIC state machine 154b may transmit an indication to one or more components of the SOC 151 to shut down to enter a safe state. At step 208, the ASIL-D PMIC state machine 154b may transmit a fault notification (which may be via an error pin) to one or more components of the SOC 151. At step 209, the ASIL-D safety island CPU 163a of the SOC 161 may transmit an indication to the SOC 161 (e.g., the ASIL-B domain 162 or the ASIL-D safety island CPU 163a) to switch to a degraded operating mode (e.g., from level 3 to level 2 or driver takeover). Imagine that Figure 5 or Figure 6 The components of the process flow can be on a single component, or can be functional components. It is also envisaged that each SOC checks each other, so Figure 5 and Figure 6 Related steps may be mirrored appropriately.
[0037] The subject matter disclosed herein related to the safety or availability of automated vehicles for Level 2 or Level 3 autonomous driving can be more frequently implemented in a vertically integrated scenario with a robust SOC 101, where one entity may be responsible for the design of a large portion of the system. For example, if the SOC 101 is designed as disclosed, an ASIL-D PMIC 104 may be sufficient to replace or supplement the MCU, which can save costs and meet the required integrity. There are multiple ways to achieve different levels of ASIL.
[0038] The disclosed subject matter may be used in or with automotive electronic components. The electronic components may be integrated into an automobile, such as an electric vehicle. The disclosed subject matter may result in a reduction in the number of components, a reduction in system complexity, or more efficient communication between components. In an exemplary implementation, the system enters a safe state, such as shutting down a functionally safe autonomous driving system application.
[0039] The methods, systems, and devices described herein can provide the use of intelligent power supplies or redundant SOCs to meet the safety integrity or availability of Level 2 or Level 3 autonomous driving systems. All combinations of the steps disclosed herein (including the removal or addition of steps or components) are contemplated in a manner consistent with other parts of the detailed description.
[0040] Disclosed herein are systems and methods for monitoring safety in an autonomous vehicle. The system may provide an ASIL-B domain; an ASIL-D safety island communicatively coupled to the ASIL-B domain; and an ASIL-D power management integrated circuit (PMIC) communicatively coupled to the ASIL-D safety island; wherein the ASIL-D PMIC monitors the operation of the ASIL-D safety island and initiates a shutdown sequence upon detection of a fault condition. The system may also include an ASIL-B PMIC communicatively coupled to the ASIL-B domain, wherein the ASIL-B PMIC includes safety mechanisms that achieve ASIL-B integrity across a safety-critical voltage rail that powers the ASIL-B domain. All combinations of this paragraph and the above paragraph (including removal or addition of steps) are contemplated in a manner consistent with the rest of the detailed description.
[0041] A method for Level 2 or Level 3 autonomous driving may include: monitoring, by an Automotive Safety Integrity Level-D (ASIL-D) power management integrated circuit (PMIC), the operation of a first ASIL-D safety island domain of a first SOC, wherein the SOC includes the first ASIL-D safety island domain communicatively connected to one or more ASIL-B subsystems of an ASIL-B domain; determining, by the ASIL-D PMIC, a fault condition associated with the first ASIL-D safety island domain; and sending an indication to enter a degraded operating mode based on determining the presence of a fault. The method may include monitoring, by a second ASIL-D safety island domain of a second SOC, the first ASIL-D safety island domain of the first SOC. Monitoring the operation of the first ASIL-D safety island includes monitoring one or more of a power supply, a temperature, or a watchdog timer of the first ASIL-D safety island. An indication to shut down one or more components of the first SOC to a safe state may be sent based on the indication of the fault condition. The degraded operating mode includes downgrading from Level 3 autonomous driving to Level 2 autonomous driving, wherein the one or more applications include autonomous driving applications. All combinations of this and the above paragraphs (including removal or addition of steps) are contemplated in a manner consistent with the rest of the detailed description.
[0042] Unless otherwise specified, an element mentioned in the singular is not intended to mean one and only one, but rather one or more. For example, "a" module may refer to one or more modules. Without further constraints, an element beginning with "a," "an," "the," or "said" does not exclude the presence of additional identical elements.
[0043] Headings and subheadings, if any, are used for convenience only and do not limit the invention. The word "exemplary" is used to mean serving as an example or illustration. To the extent that the terms "including" or "having" are used, such terms are intended to be inclusive in a manner similar to the term "comprising," as understood when "including" is used as a transitional word in a claim. Relational terms such as first and second may be used to distinguish one entity or action from another without necessarily requiring or implying any actual such relationship or order between such entities or actions.
[0044] Phrases such as an aspect, this aspect, another aspect, some aspects, one or more aspects, a specific implementation, this specific implementation, another specific implementation, some specific implementations, one or more specific implementations, an embodiment, this embodiment, another embodiment, some embodiments, one or more embodiments, a configuration, this configuration, another configuration, some configurations, one or more configurations, the subject technology, the disclosure, the disclosure, other variations thereof, etc., are for convenience and do not imply that the disclosure associated with such phrases is essential to the subject technology or that such disclosure applies to all configurations of the subject technology. The disclosure associated with such phrases may apply to all configurations or one or more configurations. The disclosure associated with such phrases may provide one or more examples. Phrases such as an aspect or some aspects may refer to one or more aspects, and vice versa, and this applies similarly to the other aforementioned phrases.
[0045] The phrase "at least one of" preceding a list of items, with the terms "and" or "or" used to separate any of those items, modifies the list as a whole, not each of the constituent items of the list. The phrase "at least one of" does not require selection of at least one item; rather, the phrase allows for a meaning that includes at least one of any of those items, and / or at least one of any combination of those items, and / or at least one of each of those items. By way of example, each of the phrases "at least one of A, B, and C" or "at least one of A, B, or C" means only A, only B, or only C; any combination of A, B, and C; and / or at least one of each of A, B, and C.
[0046] It should be understood that the specific order or level of the disclosed steps, operations or processes is an illustration of an exemplary method. Unless otherwise clearly stated, it should be understood that the specific order or level of steps, operations or processes can be performed in different orders. Some of the steps, operations or processes can be performed simultaneously. The attached method claims (if any) present the elements of various steps, operations or processes in a sample order and are not meant to be limited to the specific order or level presented. These can be performed continuously, linearly, in parallel or in different orders. It should be understood that the described instructions, operations or systems can usually be integrated together in a single software / hardware product or packaged into multiple software / hardware products.
[0047] In one aspect, the term "coupled" or the like may refer to a direct coupling. In another aspect, the term "coupled" or the like may refer to an indirect coupling.
[0048] Terms such as top, bottom, front, back, side, horizontal, vertical, etc. refer to an arbitrary reference frame other than the ordinary gravitational reference frame. Thus, such terms may extend upward, downward, diagonally, or horizontally in a gravitational reference frame.
[0049] The present disclosure is provided to enable any person skilled in the art to practice the various aspects described herein. In some instances, well-known structures and components are shown in block diagram form to avoid confusion about the various concepts of the subject technology. The present disclosure provides various examples of the subject technology, and the subject technology is not limited to these examples. Various modifications to these aspects will be readily apparent to those skilled in the art, and the principles described herein may be applied to other aspects.
[0050] All structural and functional equivalents of the various elements of the various aspects described throughout this disclosure are known or will later become known to those of ordinary skill in the art, and these equivalents are expressly incorporated herein by reference and are intended to be included in the claims. In addition, nothing disclosed herein is intended to serve the public, regardless of whether such disclosure is explicitly stated in the claims. No claim element should be interpreted under the provisions of 35 U.S.C. § 112(f) unless the element is explicitly stated using the phrase "means for..." or, in the case of a method claim, the element is stated using the phrase "step for..."
[0051] Those skilled in the art will appreciate that the various illustrative blocks, modules, elements, parts, methods and algorithms described herein can be implemented as hardware, electronic hardware, computer software or a combination thereof. In order to illustrate this interchangeability of hardware and software, various illustrative blocks, modules, elements, parts, methods and algorithms have been generally described above in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the entire system. Those skilled in the art can implement the described functionality in different ways for each specific application. Various components and blocks can be arranged differently (e.g., arranged in different orders or divided in different ways), all of which do not depart from the scope of the present subject technology.
[0052] The invention title, background technology, description of the figures, abstract of the specification and drawings are hereby incorporated into this disclosure and are provided as illustrative examples of the present disclosure rather than as limiting descriptions. This document is submitted with the understanding that they will not be used to limit the scope or meaning of the claims. In addition, in the detailed description, it can be seen that for the purpose of simplifying the present disclosure, the description provides illustrative examples and various features are grouped together in various specific implementations. The method of the present disclosure should not be interpreted as reflecting an intention that the claimed subject matter requires more features than those expressly stated in each claim. On the contrary, as reflected in the claims, the inventive subject matter lies in less than all the features of a single disclosed configuration or operation. The claims are hereby incorporated into the detailed description, with each claim independently serving as a separately claimed subject matter.
[0053] The claims are not intended to be limited to the aspects described herein, but should be given the full scope consistent with the language of the claims and encompassing all legal equivalents. Nevertheless, none of the claims is intended to encompass subject matter that fails to meet the requirements of applicable patent law, nor should they be interpreted in such a manner.
Claims
1. A method for Level 2 or Level 3 autonomous driving, the method comprising: monitoring, by an Automotive Safety Integrity Level-D (ASIL-D) power management integrated circuit (PMIC), operation of a first ASIL-D safety island domain of a first system on chip (SOC), wherein the first SOC includes the first ASIL-D safety island domain communicatively coupled to one or more ASIL-B subsystems of an ASIL-B domain; determining, by the ASIL-D PMIC, a fault condition associated with the first ASIL-D safety island domain; and An instruction to shut down one or more components of the first SOC to a safe state is sent based on determining that the fault condition exists.
2. The method according to claim 1 further comprises monitoring by a second ASIL-D safety island domain of a second SOC. 3 . The method of claim 1 , wherein monitoring the operation of the first ASIL-D safety island domain comprises monitoring one or more power supplies of power supplies of the first ASIL-D safety island domain. 4 . The method of claim 1 , wherein monitoring operation of the first ASIL-D safety island domain comprises monitoring one or more temperatures. 5 . The method of claim 1 , wherein monitoring the operation of the first ASIL-D safety island domain comprises monitoring one or more watchdog timers of the first ASIL-D safety island domain. 6 . The method of claim 1 , further comprising sending an indication to cease operation of one or more applications or to enter a degraded mode of operation based on the indication of the fault condition.
7. The method of claim 6, wherein the downgraded operating mode comprises downgrading from Level 3 autonomous driving to Level 2 autonomous driving. The method of claim 6 , wherein the one or more applications include an autonomous driving application.
9. A system for monitoring safety in an autonomous vehicle, comprising: Automotive Safety Integrity Level-B (ASIL-B) domain; An ASIL-D safety island domain, the ASIL-D safety island domain being communicatively connected to the ASIL-B domain; and An ASIL-D power management integrated circuit (PMIC) is communicatively coupled to the ASIL-D safety island domain, wherein the ASIL-D PMIC monitors operation of the ASIL-D safety island domain and initiates a shutdown sequence upon detecting a fault condition.
10. The system of claim 9, further comprising: An ASIL-B PMIC is communicatively coupled to the ASIL-B domain, wherein the ASIL-B PMIC includes a safety mechanism that implements ASIL-B integrity across a voltage rail that powers the ASIL-B domain. 11 . The system of claim 9 , wherein monitoring operation of the first ASIL-D safety island domain comprises monitoring one or more of power supplies of the first ASIL-D safety island domain.
12. The system of claim 9, wherein monitoring operation of the first ASIL-D safety island domain comprises monitoring one or more temperatures.
13. A method for Level 2 or Level 3 autonomous driving, the method comprising: monitoring, by an Automotive Safety Integrity Level-D (ASIL-D) power management integrated circuit (PMIC), operation of a first ASIL-D safety island domain of a first system on chip (SOC), wherein the first SOC includes the first ASIL-D safety island domain communicatively coupled to one or more ASIL-B subsystems of an ASIL-B domain; determining, by the ASIL-D PMIC, a fault condition associated with the first ASIL-D safety island domain; and An indication to enter a degraded mode of operation is sent based on determining that the fault condition exists. 14 . The method according to claim 13 , further comprising monitoring the first ASIL-D safety island domain of the first SOC by a second ASIL-D safety island domain of a second SOC. 15 . The method of claim 13 , wherein monitoring operation of the first ASIL-D safety island comprises monitoring one or more power supplies of the first ASIL-D safety island.
16. The method of claim 13, wherein monitoring operation of the first ASIL-D safety island comprises monitoring one or more temperatures. 17 . The method of claim 13 , wherein monitoring operation of a first ASIL-D safety island comprises monitoring one or more watchdog timers of the first ASIL-D safety island.
18. The method of claim 13, further comprising sending an indication to shut down one or more components of the first SOC to a safe state based on the indication of the fault condition.
19. The method of claim 18, wherein the downgraded operating mode comprises changing from Level 3 autonomous driving to Level 2 autonomous driving.
20. The method of claim 18, wherein the degraded operating mode comprises a shutdown of an autonomous driving application.