Communication architecture for vehicles to achieve a redundant fail-active vehicle architecture
A communication architecture with coordinated primary and secondary platforms ensures fail-active operation of steering and braking in automated vehicles, addressing the lack of fail-active components by switching between redundant systems to maintain functionality.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- SCHAEFFLER TECHNOLOGIES AG & CO KG
- Filing Date
- 2025-05-28
- Publication Date
- 2026-04-23
AI Technical Summary
Existing vehicles, particularly highly automated ones, lack fail-active components for critical systems like steering and braking, necessitating a communication architecture that ensures these functions remain operational even in the event of a fault without mechanical connections, as they rely on standard fail-passive components.
A communication architecture comprising two platforms (primary and secondary) with a coordination unit to coordinate driving functions, allowing fail-active behavior by switching between them in case of failure, ensuring redundancy and safety.
Enables fail-active operation of steering and braking functions even with standard fail-passive components, enhancing vehicle safety and reliability by maintaining functionality in the event of component failures.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a communication architecture for a vehicle, a vehicle comprising a communication architecture and a control method for a communication architecture. State of the art
[0002] In principle, it must be ensured that steering and braking are always possible in road vehicles, even in the event of a malfunction, in order to bring the vehicle to a safe stop on a predetermined path. In conventional vehicles, this is achieved through a mechanical connection between the steering wheel and the wheels, or a mechanical-hydraulic connection between the brake pedal and the brake discs. Steering and braking assistance systems based on software and electronics therefore only need to be implemented as fail-passive in conventional vehicles, since the mechanical-hydraulic fallback system allows the driver to influence the vehicle's movement even if the electronic assistance system fails.
[0003] A fail-active system for a vehicle has a safety feature that allows it to continue operating safely despite a fault or failure in any part of the system. A function provided by the system remains available even after the fault occurs. Unlike a fail-passive (fail-safe) system, which can no longer provide any function once a fault occurs, a fail-active system attempts to maintain operation and control of the vehicle until a safe handover to the driver or the vehicle reaches a safe state. A fail-active system is a safety approach where, in the event of a fault or failure, the system gradually shuts down its functions without completely disabling the vehicle. This means that the vehicle, or the function affected by the failure, does not stop abruptly (as with a fail-passive system).
[0004] The situation is different for highly automated vehicles, which must assume a safe state in the event of a malfunction even without driver intervention. Here, the mechanical connection is inherently broken, leading, for example, to so-called steer-by-wire or brake-by-wire systems, which must perform functions such as steering and braking in a fail-active manner. Some examples of fail-active systems include steering systems, braking systems, drive systems, and low-voltage power supply systems for various components. The drive system can refer to a vehicle's powertrain control unit. However, at present, no components with the necessary fail-active capabilities are available on the mass market.
[0005] In the development of a rolling chassis, the driving platform (rolling chassis) of an autonomous vehicle with SAE Level 4 must be designed in such a way that, although only standard fail-passive components are used, the circuitry results in fail-active behavior with regard to the driving functions "braking" and "steering." This also necessitates a fail-active provision of electrical low-voltage power by the rolling chassis: internally for the systems that implement steering and braking, and externally for the system of an external partner that executes the automated driving function in fail-active mode. Propulsion and other auxiliary functions, however, only need to be implemented in fail-passive mode.
[0006] The term "fail passive" means that a faulty component or function has no negative impact on other components and functions. This is usually ensured by the component or function detecting its own fault with a predetermined probability and shutting itself down. The term "fail active," on the other hand, means that a faulty component or function maintains at least some of its functionality for a predetermined period, even in the event of a single fault, whereas fail-passive components typically shut down completely in the event of a failure.
[0007] It is an object of the present invention to derive a communication architecture for a vehicle, in particular for an autonomous vehicle, e.g. for an autonomous vehicle according to SAE Level 4 or 5 or an underlying rolling chassis, in which driving functions such as "braking" and / or "steering" and / or the provision of low-voltage power fail-active capability are ensured. Disclosure of the invention
[0008] These and other problems, which will be mentioned in the following description or which can be recognized by a person skilled in the art, are solved by the subject matter of the independent claims. Advantageous embodiments and further developments can be found in the dependent claims and the following description as well as in the drawings.
[0009] The terms "fail-active" and "fail-safe" are explained below.
[0010] For example, "fail-active" can mean that the system is built from multiple fail-safe systems and has fault detection and suppression capabilities. The fail-safe systems must be able to compare their output results with each other.
[0011] "Fail-safe" is, for example, a design method for detecting the occurrence of errors in systems and bringing a machine to a safe state. In static fail-safe design, components are installed and connected to a control system in such a way that the component establishes a safe state in the event of a failure. 001
[0012] The communication architecture according to the invention for a vehicle, in particular for an autonomous vehicle, comprises a first platform, a second platform, and a coordination unit. The first platform is configured to provide a first set of driving functions. The second platform is configured to provide a second set of driving functions. The coordination unit is configured to coordinate the first set of driving functions and the second set of driving functions.
[0013] The first platform can also be referred to as the motion lane primary and the second platform as the motion lane secondary. The terms "first" and "second" do not indicate any order or prioritization of one platform over the other and can be used interchangeably. Accordingly, the motion lane primary can also correspond to the second platform, while the motion lane secondary corresponds to the first platform of the communication architecture. Both platforms can be identical or equivalent in their functional scope, or they can differ from each other. According to a preferred embodiment, however, the first set of driving functions can be active during normal operation or fault-free operation of the vehicle, while individual driving functions of the second set, or all driving functions of the second set, are used in the event of a fault.In this embodiment, the second set of driving functions represents a fallback level.
[0014] The driving functions provided by the first platform can be considered bundled within that platform. Similarly, the driving functions provided by the second platform can also be considered bundled within that platform. Therefore, each platform can provide individual driving functions or all driving functions from its respective set.
[0015] The driving functions can therefore be grouped into two platforms, the primary motion lane and the secondary motion lane, which are coordinated with each other, particularly via the coordination unit (e.g., a motion lane coordination unit), to such an extent that they do not negatively affect each other. This achieves a separation of the first set of driving functions from the second. Thus, for example, a malfunction in at least one of the driving functions of the first platform does not affect the driving functions of the second platform, and vice versa.
[0016] One can therefore say that the communication architecture provides one or more driving functions with which the vehicle can be operated. Such a driving function provided by the communication architecture can be provided by a driving function from the first set of driving functions on the one hand, and by a driving function from the second set of driving functions on the other.
[0017] Any driving function can be implemented as an autonomous driving function. This means that the respective driving function exerts an effect on the vehicle without driver intervention, such as influencing the longitudinal and / or lateral movement of the vehicle.
[0018] Each driving function can be understood as a processing path through which a corresponding effect can be imposed on the vehicle. This processing path can be implemented using software and / or hardware. Implementation using software means, in particular, that the respective driving function is partially or completely realized as a computer program executable on a data processing system, such as an electronic control unit (ECU). This allows the data processing system to process various types of information. Specifically, it enables the analysis of measured values and vehicle states and the corresponding control of the vehicle. The partial or complete implementation of a driving function using hardware can include one or more actuators in the hardware path, which allow for influencing the vehicle, particularly in terms of longitudinal or lateral control. For example...The actuators can be a braking system or one or more brake actuators, a drivetrain or a drive unit such as an engine. Alternatively or additionally, the actuators can be a steering system or a steering actuator.
[0019] The communication architecture can be configured to perform diagnostics on its components, particularly the first platform, the second platform, and / or the coordination unit. This can include diagnosing and monitoring individual driving functions from the first set of driving functions, from the second set of driving functions, from the first set of driving functions as a whole, and / or from the second set of driving functions as a whole. This allows for the determination of whether driving functions are currently available or whether they are faulty, limited, temporarily or permanently unavailable.
[0020] Alternatively or additionally, the communication architecture can be configured to receive and process an externally generated diagnostic result. This result could, for example, be generated by an external diagnostic unit designed to diagnose the communication architecture, and in particular the first platform, the second platform, and / or the coordination unit. This allows the communication architecture to receive a diagnosis and, if necessary, adjust its operation accordingly. 002
[0021] According to one embodiment, the first set of driving functions can include a longitudinal control function and / or a lateral control function and / or a low-voltage (LV) power supply function, and the second set of driving functions can include a longitudinal control function and / or a lateral control function and / or a LV power supply function. The respective longitudinal control function can be configured to control the longitudinal movement of the vehicle. In particular, the longitudinal control function can include maintaining, reducing, or increasing the longitudinal speed of the vehicle and / or the drive power of the vehicle. The respective longitudinal control function can be a drive and / or braking function. The respective lateral control function can be configured to control the lateral movement of the vehicle. In particular, the lateral control function can be a steering or control function. The longitudinal and lateral control functions thus allow for influencing or...Vehicle movement control is possible. The low-voltage (LV) power supply of the respective platform can be a function that provides the platform with electrical energy. In particular, this allows the respective set of driving functions to be powered so that they are available. This ensures that the set of driving functions, especially the respective longitudinal control function and / or the respective lateral control function, can be powered independently of each other and, for example, also independently of the other systems of the vehicle.
[0022] The communication architecture can be configured to provide at least one of the driving functions independently. Accordingly, a driving function from one set of driving functions can be replaced by the corresponding driving function from another set. This can be done without affecting the other driving functions. For example, if the driving function responsible for lateral vehicle control fails or is unavailable in the first set of driving functions, the system can switch to the corresponding driving function responsible for lateral vehicle control from the second set of driving functions. This ensures that the vehicle's lateral control remains intact even after this failure.
[0023] The communication architecture may further include a third platform that provides a third set of driving functions. These functions may be auxiliary functions, which can be fail-passive. These driving functions may include high-voltage power supply, thermal management, air suspension, and functions such as human-machine interface (HMI) and connectivity. The HMI control may specifically refer to an accelerator pedal, brake pedal, steering element such as a steering wheel, or instrument cluster. The high-voltage power supply system may refer to the battery management system and the charging and high-voltage control unit. The communication architecture may coordinate the vehicle status and / or a failure of at least one of the aforementioned driving functions via the third platform in a fail-passive manner.
[0024] In addition to the aforementioned functions, the architecture can, for example, guarantee fail-passive functionality for the rolling chassis, including the implementation of the propulsion function and other secondary functions such as ride height adjustment. Furthermore, there are overarching functions that require interaction with the aforementioned functions and lead to increased ride comfort and vehicle functionality, such as energy recuperation. In this context, the architecture can fundamentally ensure that fail-passive functions have no negative impact on fail-active functions such as steering, braking, and low-voltage power delivery.
[0025] The interface to the automated driving function of an external partner should be redundant, especially for steering and braking. Latency in the communication between the steering and braking functions of the rolling chassis and an external logic for the automated driving function (SDS) should be kept as low as possible. Furthermore, intervention by the safety driver and overriding of the automated driving function should be possible during the development phase. Integration with cloud services can be ensured while taking cybersecurity into account. The architecture can minimize the complexity of the wiring harness and support the integration of predefined ECUs for the subsystems.
[0026] At present, it can be assumed that the communication architecture can only use components that are themselves fail-passive in order to fulfill the aforementioned task. However, particularly in a system network, a fail-active function can be implemented from these fail-passive components.
[0027] Since in an autonomous vehicle from SAE Level 4 onwards no driver can take control of the vehicle in the event of a failure of electronic systems, it is necessary to implement at least the driving functions braking and steering redundantly if only standard components from the mass market are used, which only behave in fail-passive mode. 003
[0028] According to one embodiment, the first set of driving functions and the second set of driving functions can, in particular exclusively, comprise fail-passive functions. These fail-passive functions can be, as mentioned above, drive, brake, control, or steering functions. Thus, a corresponding driving function from the first set of driving functions and a corresponding driving function from the second set of driving functions can each be provided as fail-passive functions, which means less effort is required to provide the respective driving function. Corresponding driving functions as fail-active driving functions are either significantly more complex to implement, not available, or not feasible. 004
[0029] According to one embodiment, the coordination unit can be configured to coordinate the driving functions of the first and second platforms such that at least one driving function provided by the communication architecture is provided as a fail-active driving function. Accordingly, the communication architecture can convert a conventional fail-passive driving function into a fail-active driving function. However, if a driving function from one of the sets of driving functions fails or becomes unavailable, the coordination unit can coordinate these driving functions in such a way that the corresponding driving function is provided from the other set of driving functions. In this way, the driving function can continue to be provided by the communication architecture even in this case.The communication architecture thus exhibits fail-active behavior, which is realized through individual driving functions implemented as fail-passive and their coordination by the coordination unit. In other words, by coordinating the driving functions from the first and second sets of driving functions, a communication architecture exhibiting fail-active behavior can be realized from purely fail-passive components. Therefore, the proposed communication architecture enables an improvement in the availability of the corresponding driving functions and, consequently, an increase in the safety of the communication architecture.
[0030] According to the previous embodiment, the coordination unit can be configured to provide at least one driving function as a fail-active driving function via the communication architecture when a fault is detected in at least one of the first group of driving functions on the first platform. Accordingly, the communication architecture can provide an alternative control system for the fail-active provision of the failed driving function, with the same driving function being provided by the second platform. This enables independent control of at least one of the failed fail-passive systems. 006
[0031] According to one embodiment, the coordination unit can be configured to deactivate at least one driving function from the first set of driving functions and / or activate a corresponding driving function from the second set of driving functions in response to a change condition. Activation can mean bringing a non-running or deactivated system or an unused function into an active state or putting the function into operation. In other words, the task(s) previously performed by the driving function(s) from the first set of driving functions is / are now performed by the driving function from the second set of driving functions. In this way, it can be achieved that a driving function is replaced by a corresponding driving function from the other set of driving functions. However, activation can also mean increasing the activity level of a driving function if it is already in use.
[0032] The switching condition can be, for example, a failure or error in at least one driving function of the first set of driving functions. This enables a switch to a corresponding driving function of the second set of driving functions.
[0033] A change condition can be a failure of a driving function or a deliberately introduced change condition. 007
[0034] According to one embodiment, the coordination unit can further be configured such that, in response to a failure of at least one driving function from the second set of driving functions, the driving function from the first set of driving functions corresponding to the failed driving function continues to be executed as a fail-passive driving function. In this case, if this driving function fails, there is no switch to the corresponding driving function from the second set of driving functions. In other words, there is no fallback option. Consequently, the communication architecture can only provide this driving function as a fail-passive driving function. Therefore, the communication architecture can be designed to take a preventive measure to mitigate or avoid the consequences of a failure of the driving function from the first set of driving functions. For example, the vehicle can be put into a safe state, such as...to bring to a standstill. For this purpose, the still active driving function from the first set of driving functions can be used. If this is a driving function that is primarily used, the full functionality of this driving function would still be available in this situation. However, since this driving function is only available as a fail-passive driving function due to the failure of the corresponding driving function from the second set of driving functions, the risk of a total failure of both driving functions, i.e., from the first and second sets of driving functions, at an inopportune time is thus avoided. For example, if...If the driving function from the second set of driving functions is a longitudinal control function, and the corresponding longitudinal control function from the first set of driving functions provides a full range of functions, including the "drive" and "decelerate" functions, then in the event of a failure of the driving function from the second set, the full range of functions, including "drive" and "decelerate," would still be available. However, in the event of a failure of this driving function, it would no longer be possible to switch to the corresponding driving function from the second set, which, for example, might not include the "drive" function and could therefore be designed as a fallback function. Therefore, by bringing the vehicle to a safe state, it is prevented that the vehicle risks permanently losing the "decelerate" driving function at an inopportune time in this case.Alternatively, the malfunctioning driving function can be deactivated, preferably at a predefined time. Therefore, the second set of driving functions can be monitored continuously or at specific intervals. 008
[0035] According to one embodiment, the coordination unit can further be configured such that a driving function from the second set of driving functions is activated and preferably the corresponding driving function from the first set of driving functions is deactivated if a diagnosis of these driving functions from the first set of driving functions cannot be performed. In particular, the coordination unit can be designed such that the second set of driving functions is activated in its entirety and preferably the first set of driving functions is deactivated in its entirety if a diagnosis of the first set of driving functions cannot be performed. The diagnosis can be carried out during vehicle operation. In this way, it is ensured that there is no indeterminate evaluation state of the driving functions and that a driving function is always active that can also be subjected to diagnosis.If a diagnostic check cannot be performed, this may mean that the correct functioning of the first set of driving functions cannot be confirmed. The diagnostic check can be performed during vehicle operation at predetermined intervals or continuously.
[0036] The communication architecture, particularly the coordination unit, can be configured to bring the vehicle into a safe state, or to trigger the vehicle to enter a safe state, if a driving function can no longer be provided as a fail-active driving function by the communication architecture. This means that if this driving function fails, there is no further fallback option to compensate for the failed driving function. The safe state could, for example, be the vehicle being parked. Parking the vehicle could occur in a suitable location, such as a road shoulder or a parking lot. The transition to the safe state can be implemented in various ways. Depending on the criticality of the situation, the transition to the safe state can be immediate or delayed.Immediate adoption of a safe state can occur when continuing to drive the vehicle is not justifiable for safety reasons, for example, if it is expected that the vehicle would no longer have any lateral control or deceleration functions in the event of a further failure. Delayed adoption of a safe state can, for example, involve the vehicle continuing to operate for a predetermined time interval or distance and then assuming the safe state. Alternatively or additionally, it can be stipulated that the vehicle, once switched off, does not allow it to resume driving. Delayed adoption of a safe state is a sensible option when the probability of failure of the remaining driving function is comparatively low, and it is therefore safer to leave the vehicle in a parking lot or similar location.to pull over, instead of immediately assuming a safe position at the roadside or on a hard shoulder.
[0037] Up to this point, the communication architecture underlying the present invention has been described. Further aspects of the invention are described below. Features of these features, which were already described above in the context of the communication architecture, are to be understood as further developments of these features. 009
[0038] Another aspect of the invention relates to a vehicle with a communication architecture as described above, wherein the vehicle is in particular an autonomous vehicle. The communication architecture ensures that the vehicle provides the driving functions required for operation and can react accordingly in the event of a failure of the driving functions, as described above. 010
[0039] Another aspect of the invention relates to a control method for a communication architecture as described above, wherein the control method comprises the step of coordinating the first set of driving functions and the second set of driving functions. In this way, the driving functions of a vehicle can be coordinated accordingly, in particular activated and deactivated, in order to make the driving functions available as reliably as possible. 011
[0040] According to one embodiment, the coordination of the first set of driving functions and the second set of driving functions is carried out in such a way that at least one driving function is provided as a fail-active driving function. In this way, if a driving function fails or becomes unavailable, it is ensured that the vehicle can still provide the driving function to the same or at least a reduced extent. 012
[0041] According to one embodiment, in response to a switching condition, at least one driving function of the first set of driving functions is deactivated and / or a corresponding driving function of the second set of driving functions is activated. The switching condition can be, for example, a failure or error in at least one driving function of the first set of driving functions. This enables a switch to a corresponding driving function of the second set of driving functions. 013
[0042] According to one embodiment, a driving function from the second set of driving functions is activated, or the entire second set of driving functions is activated, and preferably a driving function from the first set of driving functions is deactivated, or the entire first set of driving functions is deactivated, if a diagnosis of the first set of driving functions cannot be performed. This ensures that there is no indeterminate evaluation state of the driving functions and that a driving function is always active that can also be subjected to diagnosis.
[0043] In one example, the coordination of the first set of driving functions and the second set of driving functions upon detection of a failure in one of the first set of driving functions could involve deactivating the first set of driving functions and activating a corresponding driving function from the second set. For a smooth transition, the failed driving function of the first set of driving functions could be deactivated after the corresponding driving function of the second set has been activated. Detailed description based on drawing
[0044] Further measures improving the invention are described in more detail below, together with a description of a preferred embodiment of the invention, with reference to the figures. The figures show: Fig. 1 a view of a communication architecture according to an embodiment of the invention, and Fig. 2 an exemplary view of the communication architecture from Fig. 1.
[0045] The figures are purely schematic and serve only to illustrate the invention. The same elements are identified by the same reference symbols. All drawings depict the objects shown in their respective initial positions.
[0046] In Fig. Figure 1 shows a view of a communication architecture 10 according to an embodiment of the invention.
[0047] The communication architecture 10 for a vehicle (not shown in the figures), in particular for an autonomous vehicle, comprises a first platform 11, a second platform 12, and a coordination unit 13. The first platform 11 is configured to provide a first set of driving functions. The second platform 12 is configured to provide a second set of driving functions. The coordination unit 13 is configured to coordinate the first set of driving functions and the second set of driving functions.
[0048] As in Fig. As shown in Figure 1, the driving functions are bundled into two platforms: the motion lane primary (the first platform) 11, and the motion lane secondary (the second platform) 12. Fig. 1. Each of these is equipped with a function or control section, Virtual driver (Virtual driver primary 111 and Virtual driver secondary 121), for the electronic generation of driving commands and with actuators for steering 112, 122, braking 113, 123, and propulsion 114, 124, as well as a separate on-board network 115, 125. While a failure of the "propulsion" driving function is generally not considered safety-critical, a redundant design, as in Fig. As shown in point 1, this would not actually be necessary. However, it can still be useful to increase availability.
[0049] As in Fig. As shown in Figure 1, the coordination unit 13 can comprise two independent sub-coordination mechanisms: a primary coordination 131 relating to the first platform 11 and a secondary coordination 132 relating to the second platform 12. The primary coordination 131 relates to the coordination of the driving functions of the first platform 11. The secondary coordination 132 relates to the coordination of the driving functions of the second platform 12.
[0050] An advantage of the illustrated embodiment is that the safety-critical driving functions are separated from functions with low reliability in such a way that a negative influence on the safety-critical driving functions can be ruled out. This implies that the primary and secondary motion lanes, i.e., the first platform 11 and the second platform 12, contain all the necessary capabilities, so that the vehicle state and failure coordination, referred to here as the third platform 14, cannot or must not be used to fulfill the driving functions, as a failure of this platform cannot be ruled out.
[0051] A further advantage in structuring the communication architecture 10 is to provide the redundant components with a high degree of independence in order to prevent, for example, a fault in the primary motion lane (i.e., in the first platform 11) from also resulting in a fault in the secondary motion lane (i.e., the second platform 12). However, a completely independent design is not possible because a certain degree of coordination between the two paths is essential. For example, in the event of a fault, the primary motion lane must be deactivated and the secondary motion lane activated instead.
[0052] The communication architecture 10 shown here can have one or more primary processing paths and one or more secondary processing paths. A primary processing path can include the virtual driver primary 111 and one of the primary actuators 112-115. A secondary processing path can include the virtual driver secondary 121 and one of the secondary actuators 122-125. The primary processing paths can be monitored and / or diagnosed by the primary coordination 131, and the secondary processing paths by the secondary coordination 132. Of course, the primary and secondary processing paths are not limited to the combination of virtual driver and actuator shown here. They can also include additional components.
[0053] The communication architecture 10 in Fig. 1 further comprises the third platform 14, which provides a third set of functions, including driving functions. These functions include auxiliary functions that are fail-passive, meaning they can fail. These driving functions can include high-voltage supply 141, thermal management 142, air suspension 143, and functions such as human-machine interface (HMI) 144 and connectivity 145. The communication architecture 10 can coordinate the vehicle status and / or a failure of at least one of the aforementioned driving functions 141-145 via the third platform 14 in a fail-passive manner.
[0054] Fig. Figure 2 shows an exemplary view of the communication architecture 10 from Fig. 1. In other words, in Fig. 2. A mechanism for coordination is proposed that takes into account the following objectives and constraints: - Both motion lanes off Fig. 1. They cannot negatively affect each other. - In the event of an error in Motion lane primary, i.e. the first platform 11, it is partially or completely deactivated and instead Motion lane secondary, i.e. the second platform 12, is activated. - The motion lane coordination is implemented using standard fail-passive components. However, by linking both the first platform 11 and the second platform 12, fail-active behavior of the coordination unit 13 can be achieved. - In a fault-free case, the vehicle is driven using the first platform 11, while the second platform 12 only intervenes if the first platform 11 fails.
[0055] According to the invention, the following is implemented: - Using self-diagnosis 133 (actuator diagnostics primary), the first platform 11 detects malfunctions in its own actuators 112-115, also incorporating the error information from the virtual driver primary 111. Thus, self-diagnosis 133 monitors and diagnoses the individual functional components of the first platform 11. - In the event of a fault, the primary self-diagnosis 133 informs the activation logic primary, a primary activation logic 134, which deactivates the driving commands of the virtual driver primary 111 and thus the actuators 112-115 of the first platform 11. At the same time, the activation logic secondary, a secondary activation logic 135, will activate the signal flow from the virtual driver secondary 121 to the actuators 122-125 of the motion lane secondary 12 based on this fault message. - Due to the fail-passive behavior of the primary coordination 131, a diagnostic failure cannot be ruled out. In this case, the secondary activation logic 135, which detects a malfunction of its own actuators 122-125, can also activate the corresponding secondary processing path based on missing signals from the primary self-diagnostic 133, so that the required driving function can now be provided by the second platform 12. Even if the primary processing path is error-free, but an error occurs in the second platform 12, causing the secondary processing path to malfunction, a safe fallback level is no longer guaranteed. Therefore, the vehicle must be brought to a safe state, such as a standstill, before an additional error event occurs in the primary processing path. For this reason, the secondary processing path is continuously monitored by the secondary self-diagnostics 136 (Actuator diagnostics secondary). If an error is detected, the virtual driver secondary 121 is informed accordingly so that it can initiate an appropriate response, such as bringing the vehicle to a standstill at the roadside.
Claims
[1] Communication architecture (10) for a vehicle, in particular for an autonomous vehicle, comprising: - a first platform (11) designed to provide an initial set of driving functions, - a second platform (12) designed to provide a second set of driving functions, and - a coordination unit (103) which is trained to coordinate the first set of driving functions and the second set of driving functions. [2] Communication architecture (10) according to claim 1, wherein the first set of driving functions comprises a longitudinal guidance function and / or a lateral guidance function and / or an LV power supply function, and wherein the second set of driving functions comprises a longitudinal guidance function and / or a lateral guidance function and / or an LV power supply function. [3] Communication architecture (10) according to one of the preceding claims, wherein the first set of driving functions and the second set of driving functions comprise, in particular exclusively, fail-passive functions. [4] Communication architecture (10) according to one of the preceding claims, wherein the coordination unit (103) is configured to coordinate the driving functions of the first platform (11) and the second platform (12) such that at least one driving function provided by the communication architecture (10) is provided as a fail-active driving function. [5] Communication architecture (10) according to claim 4, wherein the coordination unit (103) is configured to provide the at least one driving function through the communication architecture (10) as a fail-active driving function if a failure in at least one of the first set of driving functions of the first platform (11) is detected. [6] Communication architecture (10) according to one of the preceding claims, wherein the coordination unit (103) is configured to deactivate at least one driving function of the first set of driving functions and / or activate a corresponding driving function of the second set of driving functions in response to a change condition. [7] Communication architecture (10) according to one of the preceding claims, wherein the coordination unit (103) is further configured such that in response to a failure of at least one driving function of the second set of driving functions, the failed driving function is executed as a fail-passive function. [8] Communication architecture (10) according to one of the preceding claims, wherein the coordination unit (103) is further configured such that a driving function from the second set of driving functions is activated or the second set of driving functions is activated in its entirety and preferably a driving function from the first set of driving functions is deactivated or the first set of driving functions is deactivated in its entirety if a diagnosis of the first set of driving functions cannot be performed. [9] Vehicle comprising a communication architecture (10) according to one of claims 1-8, wherein the vehicle is in particular an autonomously driving vehicle. [10] Control method for a communication architecture (10) according to any one of the preceding claims 1-8, wherein the control method comprises the step: Coordinating the first set of driving functions and the second set of driving functions. [11] Control method according to claim 10, wherein the coordination of the first set of driving functions and the second set of driving functions is carried out such that at least one driving function is provided as a fail-active driving function. [12] Control method according to claim 10 or 11, wherein in response to a change condition at least one driving function of the first set of driving functions is deactivated and / or a corresponding driving function of the second set of driving functions is activated. [13] Control method according to one of claims 10 to 12, wherein a driving function from the second set of driving functions is activated or the second set of driving functions is activated in its entirety and preferably a driving function from the first set of driving functions is deactivated or the first set of driving functions is deactivated in its entirety if a diagnosis of the first set of driving functions cannot be made.