Fail-safe vehicle function input system

A vehicle system with a display-based redundant button addresses the lack of economic redundancy in critical systems by enabling continued vehicle control through a fail-safe mechanism.

WO2025184286A1PCT designated stage Publication Date: 2025-09-04FISKER IP AUSTRIA ASSETS TRUST
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/017510
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-27
Filing Date
2025-02-27
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

Conventional vehicles lack economically feasible redundant input mechanisms for critical systems, leading to potential safety risks in case of switch malfunctions, as safety standards do not mandate hardware redundancy for all systems.

Method used

A switch-controlled vehicle function system with a display that displays a redundant button on the display when the switch malfunctions, allowing the operator to control the vehicle function directly through the display.

Benefits of technology

Enhances safety and reliability by providing redundant input options, ensuring vehicle operation even in the event of switch failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025017510_04092025_PF_FP_ABST
    Figure US2025017510_04092025_PF_FP_ABST
Patent Text Reader

Abstract

According to one aspect of the invention, a system comprises a switch configured to control a vehicle function; a display; a controller configured to: determine that the switch has malfunctioned; in response to determining the switch has malfunctioned, display a button on the display, the button configured to control the vehicle function when activated.
Need to check novelty before this filing date? Find Prior Art

Description

FAIL-SAFE VEHICLE FUNCTION INPUT SYSTEMTECHNICAL FIELD

[0001] The present disclosure relates to the field of vehicle input systems, in particular fail-safe systems for vehicle inputs.BACKGROUND

[0002] Conventional vehicles have acoustic and visual feedback mechanisms, such as tell-tales and tones, to inform the vehicle users of faults and malfunctions in the vehicle’s systems. Vehicles may store Diagnostic Troubleshooting Codes (DTC) to provide details about the malfunctions that occur. Conventionally, these codes could only be accessed using specialized tools, such as On-board Diagnostic (OBD) readers. Recently, some vehicles have incorporated mechanisms to display the DTC and additional information to notify users of the detected faults and malfunctions.

[0003] Recent functional safety standards have resulted in a fail-safe approach to critical vehicle systems by using redundant hardware and software mechanisms. Systems may also implement reduced functionality or limp-home modes in response to system failures. However, hardware redundancy is not economically feasible for all vehicle systems. As a result, some systems which may be critical from a user perspective, are not required by safety standards to have redundancy.SUMMARY

[0004] According to one aspect of the invention, a system comprises a switch configured to control a vehicle function; a display; a controller configured to: determine that the switch has malfunctioned; in response to determining the switch has malfunctioned, display a button on the display, the button configured to control the vehicle function when activated.

[0005] According to another aspect of the invention, a method for a vehicle, the method comprises the steps of determining that a switch has malfunctioned, the switch configured to control a vehicle function; in response to determining the switch has malfunctioned, displaying a button on a display, the button configured to control the vehicle function when activated.

[0006] The aspects above achieve increased safety and reliability by providing redundant inputs that enable the operator to control the vehicle even in the case of a malfunction. These and other objects, features, and advantages of the present invention willbecome more apparent from the following description when taken in connection with the accompanying drawings.BRIEF DESCRIPTION OF THE DRAWINGS

[0007] FIG. 1 is an illustration of an exemplary embodiment of a fail-safe system for a vehicle.

[0008] FIG. 2 is an illustration of an exemplary embodiment of a fail-safe operation of a vehicle system.DETAILED DESCRIPTION

[0009] Figure 1 illustrates a fail-safe system 100 for providing redundant inputs for functions of a vehicle in the event that a switch 102 malfunctions. An operator of the vehicle controls a function of the vehicle by activating switch 102. The vehicle function may be for example: activating a horn; adjusting the speed of windshield wipers; activating turn signals; activating headlights; raising windows; locking doors; opening a trunk or tailgate; activating a vehicle mode such as traction control, economy mode, performance mode; turning off power, etc. Switch 102 corresponds to the particular vehicle function, such as a turn signal stalk switch for activating the turn signal. Switch 102 may be a momentary switch or button, a multiposition switch or button, a pressure switch, a potentiometer switch, a j oystick with a hall effect or resistor sensor, a touch switch with capacitive or resistive sensor, or any other switch or button conventionally found in a vehicle.

[0010] Controller 101 receives a signal directly from switch 102 or indirectly from an additional controller 103 and controls an actuator 104 based on the signal. System 100 is also provided with a display 105. In the event that controller 101 determines that switch 102 is malfunctioning, controller 101 causes display 105 to display a button 106 which can be used as a fail-safe input for the operator to control the vehicle function.

[0011] Controller 101 is programmed to control the fail-safe system 100. Controller 101 may be a standalone control unit, a control unit that controls the function of multiple vehicle functions, or a module in another control unit or virtualized on another control unit in the vehicle. Controller 101 may include a processor, random access memory (RAM), storage, and input and output ports. The processor may be one or more microprocessors. The RAM functions as a work memory that temporarily stores data to be processed by processor. The storage is capable of saving information that has been put therein. The storage may include aread only memory (ROM) and a rewritable non-volatile memory. As the processor executes a program stored in storage, various types of control are carried out. Additional controllers include similar hardware configurations as controller 101.

[0012] Display 105 may be, for example, a liquid crystal display (LCD), a light emitting diode display (LED), an organic light emitting diode displays (OLED), a touch display, or other known displays. Display 105 may be a cockpit display behind a steering wheel of the vehicle. Display 105 may be a center infotainment display located in a center of the instrument panel. Display 105 may be a display external to the vehicle, such as on a mobile phone or a diagnostic device. Display 105 has a corresponding input mechanism. In one example, the input mechanism is a touchscreen configured to receive touch input from an operator. In another example, the input mechanism may be a pointing device such as a mouse, rollerball, or scrollwheel with mechanical buttons for selecting.

[0013] Figure 2 illustrates an operation 200 of system 100 executed by controller 101. Operation 200 begins with step 201 when controller 101 receives a signal from switch 102 or additional controller 103.

[0014] Next in step 202, controller 101 determines whether switch 102 is malfunctioning based on the signal. In one example, switch 102 is a normally off momentary switch, such as a horn switch, when controller 101 receives a signal indicating the switch is in the on position for more than a predetermined time, switch 102 may be stuck. In another example, switch 102 may be a multi -position switch, such as a windshield wiper stalk switch, and controller 101 receives a signal from switch 102 that does not match a signal received from additional controller 103. In another example, the signal received from additional controller 103 may be a DTC indicating that switch 102 has malfunctioned. In another example, controller 101 receives a signal from switch 102 outside of a predetermined range. Controller 101 may determine that switch 102 is malfunctioning when the signal is different than expected.

[0015] Operation 200 proceeds to step 203 when controller 101 has determined a malfunction. Controller 101 sends a signal to display 105 to display button 106. Display 105 may normally include multiple elements of a Graphical User Interface (GUI). Button 106 may overlay the other elements of the GUI. Button 106 is only displayed on display 105 when controller 101 determines that switch 102 has malfunctioned. In another embodiment, button 106 may be normally displayed but has its state changed when controller 101 determines that switch 102 has malfunctioned. For example, the color or appearance of the button may be changed. The displaying of button 106 may additionally be accompanied by an error messageor tell-tale symbol displayed on display 105 or an additional display. An audible tone may be played when the button and / or error message is displayed.

[0016] Button 106 may, for example, be activated when an operator presses on the input mechanism. When the button 106 is activated, in step 204 the input mechanism of display 105 sends a signal to controller 101 indicating that button 106 has been activated. Controller 101 controls actuator 104 directly by sending a signal to actuator 104 or indirectly sending a signal to additional controller 103. The state of button 106 may also be changed indicating that the button has been activated.

[0017] In some embodiments, controller 101 may determine that switch 102 is no longer malfunctioning. Controller 101 may determine that switch 102 is no longer malfunctioning when the input signal returns to an expected value. Controller 101 may then send a signal to display 105 to remove button 106 or otherwise change the state of the button 106.

[0018] In some embodiments, system 100 may have additional switches corresponding to the same or additional functions. Each switch may send a signal to a separate corresponding controller or multiple switches may send signals to the same controller. System 100 may have multiple displays. When the controller(s) determine that a switch has malfunctioned, the controller(s) may display a button on one or multiple displays. When the controller(s) determine that multiple switches have malfunctions, additional buttons may be displayed on the same or different displays.

[0019] The included descriptions and figures depict specific implementations to teach those skilled in the art how to make and use the best mode. For teaching inventive principles, some conventional aspects have been simplified or omitted. Those skilled in the art will appreciate variations from these implementations that fall within the scope of the invention. Those skilled in the art will also appreciate that the features described above can be combined in various ways to form multiple implementations. As a result, the invention is not limited to the specific implementations described above, but only by the claims and their equivalents.

Claims

CLAIMSWhat is claimed is:

1. A system comprising: a switch configured to control a vehicle function; a display; and a controller configured to: determine that the switch has malfunctioned; and in response to determining the switch has malfunctioned, display a button on the display, the button configured to control the vehicle function when activated.

2. The system of claim 1, wherein the controller is further configured to determine that the switch has malfunctioned by detecting that the switch is in a position for more than a predetermined time.

3. The system of claim 1, wherein the controller is further configured to determine that the switch has malfunctioned by receiving a diagnostic troubleshooting code from another controller.

4. The system of claim 1, wherein the controller is further configured to determine that the switch has malfunctioned by comparing a signal received from the switch and another signal received from another controller.

5. The system of claim 1, wherein the controller is further configured to: display a graphical user interface (GUI) containing elements on the display; and overlay the button over element of the GUI.

6. The system of claim 1, wherein the controller is further configured to only display the button when the switch is determined to be malfunctioning.

7. The system of claim 1, wherein the controller is further configured to: in response to determining that the switch is no longer malfunctioning, remove the button from the display.

8. The system of claim 1, wherein the display includes a touchscreen configured to receive touch input and the button is activated by pressing on the touchscreen.

9. The system of claim 1, wherein the vehicle function is activating a horn, windshield wiper, turn indicator, headlight, window opening, door locking, or door opening mechanism.

10. The system of claim 1, wherein the controller is further configured to in response to the button being activated, send a signal to control an actuator configured to perform the vehicle function.

11. A method for a vehicle, the method comprising: determining that a switch has malfunctioned, the switch configured to control a vehicle function; and in response to determining the switch has malfunctioned, displaying a button on a display, the button configured to control the vehicle function when activated.

12. The method of claim 11, wherein determining the switch has malfunctioned comprises: detecting the switch is in a position for more than a predetermined time.

13. The method of claim 11, wherein determining the switch has malfunctioned comprises: receiving a diagnostic troubleshooting code from another controller.

14. The method of claim 11, wherein determining the switch has malfunctioned comprises: comparing a signal received from the switch and a signal received from another controller.

15. The method of claim 11, comprising: displaying a graphical user interface (GUI) containing elements on the display; and overlaying the button over element of the GUI.

16. The method of claim 11, wherein displaying the button comprises: displaying the button only when the switch is determined to be malfunctioning.

17. The method of claim 11, comprising: in response to determining that the switch is no longer malfunctioning, removing the button from the display.

18. The method of claim 11, wherein the display includes a touchscreen configured to receive touch input and the button is activated by pressing on the touchscreen.

19. The method of claim 11, wherein the vehicle function is activating a horn, windshield wiper, turn indicator, headlight, window opening, door locking, or door opening mechanism.

20. The method of claim 11, further comprising: in response to the button being activated, sending a signal to control an actuator configured to perform the vehicle function.

Citation Information

Patent Citations

  • System and Method for Button Failure Processing in Car Audio System

    KR102074759B1

  • Interface for vehicle function control via a touch screen

    US20100318266A1

  • Vehicle information display apparatus and method

    US20220118851A1

  • Virtual display touch screen diagnostic system

    US20220397976A1

  • Display apparatus and control method therefor

    WO2023070472A1