Autonomous Vehicle Safety Architecture With Triple-Redundant Fault Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Autonomous vehicle systems face challenges due to high costs and complexity in implementing automated systems, requiring significant expertise and proprietary technologies, which can lead to system failures and limited compatibility, making it difficult for manufacturers to integrate into mainstream vehicles without partnering with third-party providers.
Innovation Solution
A distributed sensor system architecture with modular design and real-time data bus for data communication, enabling standardization and ease of updates, along with safety managers that monitor and manage component failures to ensure continued safe operation even when individual components fail, using triple modular redundancy for fault tolerance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized logging and data processing computer is used to receive sensor data input, then data processing can be consolidated, but the system becomes susceptible to failure and can unexpectedly shut-down due to cascading errors
Solution Approach 1:
The patent divides the centralized autonomous vehicle system into multiple independent distributed nodes, each capable of autonomous operation. This segmentation prevents cascading failures from propagating through the entire system, as each node operates independently with its own processing capabilities, thereby maintaining reliability while managing complexity.
Solution Approach 2:
The patent introduces a standardized communication interface and protocol as an intermediary layer between distributed nodes. This mediator enables seamless data exchange and coordination among independent nodes without requiring a centralized control point, thus improving reliability while keeping the overall system architecture manageable.
2Adaptability or versatility
If automobile companies develop their own proprietary systems and technology infrastructure, then they can have customized solutions, but it is cost prohibitive and difficult to include in mainstream consumer vehicles
Solution Approach 1:
The patent creates a universal platform with standardized interfaces and modular components that can be configured for different vehicle types and applications. This universality allows manufacturers to deploy autonomous vehicle systems across mainstream consumer vehicles without incurring prohibitive customization costs, while still maintaining adaptability through modular configuration.
Solution Approach 2:
The patent employs standardized interface specifications and communication protocols that can be replicated across multiple nodes and implementations. This copying approach enables consistent, low-cost deployment of autonomous vehicle systems across different manufacturers and vehicle platforms, reducing manufacturing complexity and cost.
3Productivity
If third-party partners are used to provide autonomous vehicle systems, then time to market decreases, but the company becomes tied to a third party proprietary system which may be undesirable
Solution Approach 1:
The patent segments the autonomous vehicle system into independent, standardized modules that can be developed by third parties but integrated without creating proprietary dependencies. This segmentation allows rapid integration of third-party components while maintaining system independence through standardized interfaces, thus achieving fast time to market without sacrificing flexibility.
Solution Approach 2:
The patent inverts the traditional proprietary model by making the interface and communication protocols open and standardized, while allowing implementation details to be proprietary. This inversion enables companies to use third-party systems rapidly while maintaining independence and flexibility through the open interface layer.
Data Source
AI summary
In embodiments of an autonomous vehicle platform and safety architecture, safety managers of a safety-critical system monitor outputs of linked components of the safety-critical system. The linked components comprise at least three components, each of which is configured to produce output indicative of a same event independent from the other linked components by using different input information than the other linked components. The safety managers also compare the outputs of the linked components to determine whether each output indicates the occurrence of a same event. When the output of one linked component does not indicate the occurrence of an event that is indicated by the outputs of the other linked components, the safety managers identify the one linked component as having failed. Based on this, the outputs of the other linked components are used to carry out operations of the safety-critical system without using the output of the failed component.


