Dual-Control Autonomous Driving Architecture for Fail-Safe Takeover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single-architecture autonomous driving systems cannot achieve the required ASIL D-level functional safety and reliability, as they fail when any controller or actuation mechanism fails at a single point, which is critical for highly autonomous driving levels L3 and L4.
Innovation Solution
A dual-control system architecture comprising a main control system and a backup control system, where the main control module monitors real-time status and sends failure notifications to the backup control module, allowing the backup execution modules to execute backup control instructions, ensuring continuous vehicle operation even if the main system fails.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single-architecture autonomous driving control system is used, then the device complexity is reduced, but the reliability cannot achieve ASIL D-level functional safety
Solution Approach 1:
The autonomous driving control system is segmented into a main control system and a backup control system, each with independent control modules and execution modules. This segmentation allows the system to maintain ASIL D-level functional safety by isolating failure domains while reducing overall complexity through modular design where each segment follows a standardized architecture.
Solution Approach 2:
The patent applies local quality by implementing redundancy only in critical control pathways. The main control system handles normal operations with full functionality, while the backup control system is activated only upon detection of main system failure. This localized application of redundancy optimizes reliability without unnecessarily duplicating the entire system.
2Reliability
If the main control system fails at a single point, then the reliability is compromised, but adding backup systems increases device complexity
Solution Approach 1:
The backup control system is prepared in advance with pre-configured control parameters and execution readiness. The main control module continuously monitors system status and can immediately trigger the backup system upon detecting failure, eliminating the need for complex real-time decision-making during failure transitions and reducing overall system complexity.
Solution Approach 2:
The backup control system uses a simplified copy of the main control architecture, replicating only the essential control modules and execution pathways needed for safe operation. This copying approach ensures single-point failure resistance while keeping the backup system less complex than a full duplicate, as it focuses only on critical functions.
3Reliability
If the backup execution modules are activated, then the reliability is improved, but the response time may be affected
Solution Approach 1:
The backup execution modules maintain continuous readiness to execute control instructions even while dormant. The main control module continuously monitors system health and can immediately transfer control to the backup system upon failure detection. This continuity approach ensures that the backup system requires minimal activation time, improving reliability without significant response time penalty.
Solution Approach 2:
The main control module implements continuous feedback monitoring of the main control system's operating status. This real-time feedback enables immediate detection of failures and rapid activation of the backup system, minimizing the time loss during failure transitions while ensuring continuous reliable operation.
Data Source
AI summary
An autonomous driving control system, comprising a main control system and a backup control system. The main control system comprises a main control module and main execution modules, and the backup control system comprises a backup control module and backup execution modules; the main control module monitors an operating status of the main control system in real time; the main control module further sends, when detecting that a failure occurs in the main control system, a failure notification to the backup control module, and sends a response termination control instruction to each of the main execution modules, the response termination control instruction being a control instruction for instructing each of the main execution modules not to respond to any control over a vehicle; and the backup control module controls, after receiving the failure notification, the backup execution modules to start to execute a backup control instruction.
