Central Control Unit Segmentation for Fault Tolerance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Designing electronic systems for autonomous driving in vehicles to achieve required functionality and reliability at reasonable costs is challenging, especially since tripling electronics for error masking is not feasible due to cost constraints in vehicle electronics.
Innovation Solution
Dividing the central control unit into two independent fault containment units (FCUs) with separate power supplies and galvanically isolated communication, allowing each FCU to maintain limited functionality with its assigned sensors in case of failure, ensuring the vehicle can be safely controlled even if one FCU fails.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If three independent computer systems are used to ensure fault tolerance, then system reliability is improved, but production cost increases significantly
Solution Approach 1:
The system is divided into two functionally independent fault containment units (FCU1 and FCU2), each capable of independent operation. This segmentation allows the system to achieve fault tolerance without requiring three complete systems, as each FCU can maintain essential functions independently when the other fails.
Solution Approach 2:
Both fault containment units are integrated onto a single circuit board, merging hardware resources while maintaining functional independence through galvanic isolation. This combining approach reduces production costs by eliminating the need for three separate physical systems while preserving fault tolerance capabilities.
2Reliability
If electronic components are tripled for error masking, then system safety is improved, but device complexity increases
Solution Approach 1:
The control unit is segmented into two fault containment units with distinct sensor assignments and independent processing paths. This segmentation provides safety through functional independence without requiring triple redundancy of all electronic components.
Solution Approach 2:
Galvanic isolation acts as an intermediary between the two fault containment units, preventing fault propagation while allowing controlled data exchange. This intermediary mechanism enables safety without direct electrical connection, reducing the complexity of inter-unit wiring and component requirements.
3Reliability
If fault containment units are galvanically isolated, then fault propagation is prevented, but communication complexity increases
Solution Approach 1:
Galvanic isolation serves as the intermediary that prevents fault propagation while enabling controlled communication between fault containment units. This isolation mechanism maintains reliability by blocking electrical faults while allowing functional data exchange through defined communication protocols.
Solution Approach 2:
The communication system between fault containment units is designed to handle multiple functions including data exchange, status monitoring, and coordinated control. This multi-functionality reduces the need for separate dedicated communication channels for each purpose, simplifying the overall communication architecture despite the galvanic isolation requirement.
Data Source
Figure 1~2
AI summary
The invention relates to a method for handling faults in a central control device, wherein the control device comprises a distributed computer system (100), to which distributed computer system (100) sensors (112, 113, 122, 123) are connected or can be connected, wherein the distributed computer system (100), in particular all components of the computer system, is/are divided between a first fault containment unit FCU1 (101) and a second fault containment unit FCU2 (102), wherein the FCU1 (101) and the FCU2 (102) are each supplied via a separate, independent power supply, and wherein the FCU1 (101) and the FCU2 (102) interchange data solely via DC-isolated lines, and wherein some of the sensors are connected at least to the FCU1 (101) and the others of the sensors are connected at least to the FCU2 (102), and wherein the FCU1 (101) and the FCU2 (102) are connected to a redundantly designed communication system (131, 132) having one or more actuators, with the result that, if the FCU1 fails, the FCU2 maintains a limited functionality using the sensors assigned to the FCU2, and, if the FCU2 fails, the FCU1 maintains a limited functionality using the sensors assigned to the FCU1.