How to Select Autonomous Driving Fail-Safe Architectures for Steering
Overview of Technical Issues:
The autonomous driving steering system exhibits insufficient fail-safe capability when critical components fail—specifically, when the control processor or steering actuator experiences faults, the current architecture cannot maintain minimum safe steering control authority, leading to potential loss of vehicle directional control and endangering passenger safety; the goal is to select an architecture that ensures graceful degradation and maintains basic steering functionality under single-point or multiple-point component failures.
Solution directions generated for this problem
Problem Direction 1 :
ImproveSystem functional redundancy capability
VSConstraintSystem architecture complexity
Inspiration 1 : Cross-domain reference
Application Principle: #1 Segmentation
Cross-domain applicability
Subscription concealed identifier
Innovative Solution Refine solution
Modular Independent Channel Steering Architecture with Simplified State Machines
Split redundancy into independent modules to reduce validation complexity
How to solve :
- Divide steering control into two independent channels, each with dedicated processor, actuator, and power supply—each channel runs simplified 8-state control logic instead of monolithic 25+ state system
- Implement hardware-based channel isolation using separate CAN buses and power domains—each channel operates autonomously without inter-channel state synchronization during normal operation, eliminating complex arbitration logic
- Deploy analog watchdog circuit (response time <5ms) monitoring each processor's PWM heartbeat signal—upon detecting heartbeat loss (tolerance ±10%), hardware relay automatically switches actuator authority to healthy channel within 15ms, bypassing software arbitration
Expected Effect : State machine complexity reduced 65%; failover time <20ms; single-point failure maintains 55% control authority
Risk Control :
- channel synchronization drift during extended operation
- hardware watchdog false-trigger rate
- independent channel calibration consistency
Problem Direction 2 :
ImproveFault detection coverage
VSConstraintDiagnostic resource consumption
Inspiration 1 : Cross-domain reference
Application Principle: #32 Color changes
Cross-domain applicability
HDMI converter with temperature sensing coating structure
Innovative Solution Refine solution
Thermochromic Indicator-Based Passive Fault Detection for Steering Actuators
Passive degradation monitoring via color-changing materials
How to solve :
- Coat actuator motor housing with thermochromic ink layer (color transition at 85°C ±3°C) that visually indicates thermal anomalies from degraded performance — 20% response delay causes 15-20°C temperature rise detectable within 30-40ms thermal time constant
- Embed low-power optical sensor array (3 photodiodes, <0.3W total) monitoring ink color change via reflected light intensity — threshold detection triggers processor interrupt only when degradation occurs, eliminating continuous 15-20% computation load
- Integrate passive current-ripple signature circuit using LC resonant filter tuned to 2-5kHz actuator fault harmonics — analog comparator flags abnormal ripple amplitude (>25% baseline) via hardware interrupt, consuming <0.5W versus 8W software-based spectral analysis
Expected Effect : Processor load -85% (from 20% to 3%), power -90% (from 10W to 1W), detection latency <50ms maintained
Risk Control :
- thermochromic ink aging and calibration drift
- ambient temperature interference on color transition threshold
- optical sensor contamination reducing detection reliability
Problem Direction 3 :
ImproveControl authority transfer speed
VSConstraintDiagnostic resource consumption
Inspiration 1 : Cross-domain reference
Application Principle: #10 Preliminary action
Cross-domain applicability
Enhancing processing performance of a DNN module by bandwidth control of fabric interface
Innovative Solution Refine solution
Snapshot-based periodic state pre-loading for rapid failover
Pre-load backup processor with periodic state snapshots to eliminate real-time synchronization overhead
How to solve :
- Implement periodic state snapshot transfer every 100ms from primary to secondary processor, capturing control trajectory, vehicle speed, and steering angle — eliminates continuous mirroring overhead
- Secondary processor maintains shadow-mode execution using last snapshot, autonomously extrapolating control commands based on stored trajectory model — ready for instant takeover without state reconstruction
- Deploy hardware watchdog circuit monitoring primary processor heartbeat at 10ms intervals, triggering MOSFET-based actuator power switching to secondary channel within 15ms upon failure detection — no software arbitration required
Expected Effect : Failover time <40ms; sync power reduced from 8W to 1.2W; processor load reduced from 18% to 3%
Risk Control :
- snapshot staleness during rapid maneuvers
- extrapolation model accuracy degradation
- watchdog false-trigger sensitivity
Problem Direction 4 :
ImproveSystem functional redundancy capability
VSConstraintComponent integration cost
Inspiration 1 : Cross-domain reference
Application Principle: #6 Universality
Cross-domain applicability
Power and data center (PDC) for automotive applications
Innovative Solution Refine solution
Multi-functional integrated steering control unit with shared actuator architecture
Shared actuator serves multiple control paths
How to solve :
- Design a triple-winding brushless motor actuator where each winding independently provides 40% steering authority
- any two windings combined deliver 80% control, eliminating separate actuator duplication and reducing BOM cost increase from 50% to 18%
- Integrate dual-core lockstep processor with shared power stage in single PCB module — each core drives separate motor winding through isolated gate drivers, cutting wiring harness complexity by 65% and assembly time by 55%
- Implement analog current-sense redundancy using three independent Hall-effect sensors (one per winding) for cross-validation
- hardware comparator flags ≥20% deviation within 15ms, triggering winding isolation via MOSFET matrix without processor intervention
Expected Effect : BOM cost +18% vs +50% baseline; 50% steering authority under single-point failure, 40% under dual-point failure; failover time <30ms
Risk Control :
- motor winding thermal imbalance risk
- gate driver isolation failure mode
- current sensor calibration drift across temperature range
Problem Direction 5 :
ImproveControl authority transfer speed
VSConstraintSystem architecture complexity
Inspiration 1 : Cross-domain reference
Application Principle: #10 Preliminary action
Cross-domain applicability
Reporting beam failure
Innovative Solution Refine solution
Pre-synchronized shadow-mode backup processor with snapshot-based failover
Run secondary processor in shadow mode executing identical control algorithm with outputs disabled, eliminating complex arbitration state machines
How to solve :
- Pre-load backup processor with vehicle state snapshot every 150ms via low-bandwidth CAN message (steering angle, velocity, trajectory parameters)
- snapshot transmission consumes <3% bus bandwidth and <1W power, avoiding continuous high-frequency mirroring
Expected Effect : Implement <strong>hardware watchdog circuit</strong> monitoring primary processor heartbeat at 10ms intervals; upon missing two consecutive pulses, MOSFET switch matrix automatically enables secondary processor outputs within 15ms, bypassing software arbitration
Risk Control :
- Deploy state continuity buffer in secondary processor storing last three snapshots
- upon takeover, interpolate current state from 150ms-old snapshot using vehicle dynamics model, achieving control continuity with <8° steering deviation during transition
