Low-Level Safety Platform for Autonomous Vehicle Fallback Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current autonomous vehicle systems lack a reliable low-level safety platform to ensure safe operation in case of computing system failures or communication losses, which can lead to catastrophic consequences.
Innovation Solution
A low-level safety platform system and method that facilitates fallback planning and execution, allowing autonomous vehicles to transition between primary and fallback operation modes, using a fallback controller to generate and execute secondary trajectories based on stored inputs and sensor data, ensuring safe operation even when the primary computing system fails or loses communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a computing system is designed to be auto-grade and resistant to failing, then reliability is improved, but device complexity increases
Solution Approach 1:
The system is divided into two independent computing systems: a primary computing system for normal autonomous vehicle operations and a secondary computing system specifically dedicated to safety-critical functions. This segmentation allows each system to be optimized for its specific purpose, with the secondary system providing reliability without requiring the entire system to be overly complex.
Solution Approach 2:
A safety platform acts as an intermediary layer between the primary computing system and the vehicle control systems. This intermediary monitors the primary system's outputs and can intervene by generating alternative control commands when safety concerns are detected, providing reliability through an additional layer of verification without directly complicating the primary computing system.
2Reliability
If backup trajectories are created with a computing system capable of assuring minimum risk condition, then safety is improved, but the system becomes useless when communication is lost
Solution Approach 1:
The secondary computing system pre-generates multiple backup trajectories and stores them locally in memory before any failure occurs. These pre-computed trajectories are ready for immediate execution if communication with the primary system is lost, eliminating the need for real-time computation during emergencies and ensuring the safety platform remains functional independently.
Solution Approach 2:
The system dynamically switches between operating modes: normally relying on the primary computing system, but automatically transitioning to the secondary computing system when communication failures or anomalies are detected. This dynamic adaptation allows the system to maintain safety functionality across varying operational conditions without requiring constant redundancy.
3Reliability
If redundant processing systems are implemented, then reliability is improved, but cost and hardware requirements increase
Solution Approach 1:
Instead of duplicating the entire primary computing system, the secondary computing system is designed with local quality appropriate for its specific safety function. It contains only the necessary components for generating and executing backup trajectories and safety monitoring, rather than full autonomous driving capabilities, reducing hardware quantity while maintaining reliability for safety-critical operations.
Solution Approach 2:
The secondary computing system creates a simplified copy or representation of essential safety functions rather than replicating the entire primary system. It copies only the critical trajectory generation and safety verification capabilities needed for emergency operations, reducing hardware requirements while providing sufficient reliability for safety purposes.
Data Source
AI summary
A system 100 for autonomous vehicle operation can include: a low-level safety platform 130; and can optionally include and/or interface with any or all of: an autonomous agent 102, a sensor system, a computing system 120, a vehicle communication network 140, a vehicle control system 150, and/or any suitable components. The system functions to facilitate fallback planning and/or execution at the autonomous agent. Additionally or alternatively, the system can function to transition the autonomous agent between a primary (autonomous) operation mode and a fallback operation mode.


