Chiplet Functional Safety Architecture for ASIL-D Autonomous Driving

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current autonomous driving systems face challenges in achieving robust safety integrity levels due to non-deterministic inference models, making it difficult to certify and provide an ASIL rating for the overall system.

Innovation Solution

A computing system with MSoC arrangements, including a primary and backup SoC, executes a FuSa program to monitor shared memory, compare and verify independent pipeline outputs, and generate error correction codes for communications between chiplets, using dedicated FuSa CPUs for enhanced ASIL rating.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-deterministic inference models are used for autonomous driving tasks, then processing flexibility and adaptability are improved, but system reliability and ability to achieve ASIL ratings deteriorate

Engineering Contradiction:
Improveinference model flexibilityVSAvoidASIL rating capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the autonomous driving computation into multiple independent pipelines (e.g., perception pipeline, object detection pipeline, control pipeline) that can be independently verified and validated. Each pipeline processes specific aspects of autonomous driving, allowing deterministic verification of individual components while maintaining overall system flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different verification and validation approaches are applied to different parts of the system based on their specific requirements. Critical safety functions receive higher levels of deterministic verification, while less critical functions can use more flexible approaches, optimizing the balance between reliability and adaptability.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If complex perception and object detection tasks are implemented, then system functionality and versatility are improved, but device complexity and certification difficulty increase

Engineering Contradiction:
Improveperception and detection capabilityVSAvoidcertification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Complex perception and detection tasks are divided into separate modular pipelines, each handling specific functions (e.g., image processing, sensor fusion, object classification). This modular structure simplifies certification by allowing each module to be independently validated and tested.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Standardized interfaces and communication protocols are introduced between different processing modules, acting as intermediaries that simplify integration and verification. These standardized connections reduce the overall system complexity and make certification more manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If redundant SoC arrangements with FuSa programs are implemented, then system reliability and ASIL ratings are improved, but device complexity and computational overhead increase

Engineering Contradiction:
Improvefunctional safety assuranceVSAvoidSoC architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The functional safety verification functions are merged into the main processing pipelines rather than being completely separate systems. The FuSa programs execute alongside the primary processing tasks, sharing computational resources and reducing overall system complexity while maintaining safety assurance.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The redundant SoC arrangements are designed with multi-functional capabilities, where the same hardware resources can serve both primary processing functions and functional safety verification. This universal design reduces the need for completely separate dedicated safety hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12621182B2Functional safety for system-on-chip arrangements
Publication Date: 2026.05.05 MERCEDES BENZ GROUP AG
  • US12621182B2 patent drawing
  • US12621182B2 patent drawing
  • US12621182B2 patent drawing

AI summary

A sensor data input chiplet obtains sensor data from a sensor system. A central chiplet executes a functional safety program to dynamically compare and verify output of workloads being executed by a set of workload processing chiplets, where the workloads are executed across the set of workload processing chiplets based on the sensor data.