Chiplet Functional Safety Architecture for ASIL-D Autonomous Driving
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current autonomous driving systems face challenges in achieving robust safety integrity levels due to non-deterministic inference models, making it difficult to certify and provide an ASIL rating for the overall system.
Innovation Solution
A computing system with MSoC arrangements, including a primary and backup SoC, executes a FuSa program to monitor shared memory, compare and verify independent pipeline outputs, and generate error correction codes for communications between chiplets, using dedicated FuSa CPUs for enhanced ASIL rating.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If non-deterministic inference models are used for autonomous driving tasks, then processing flexibility and adaptability are improved, but system reliability and ability to achieve ASIL ratings deteriorate
Solution Approach 1:
The system segments the autonomous driving computation into multiple independent pipelines (e.g., perception pipeline, object detection pipeline, control pipeline) that can be independently verified and validated. Each pipeline processes specific aspects of autonomous driving, allowing deterministic verification of individual components while maintaining overall system flexibility.
Solution Approach 2:
Different verification and validation approaches are applied to different parts of the system based on their specific requirements. Critical safety functions receive higher levels of deterministic verification, while less critical functions can use more flexible approaches, optimizing the balance between reliability and adaptability.
2Adaptability or versatility
If complex perception and object detection tasks are implemented, then system functionality and versatility are improved, but device complexity and certification difficulty increase
Solution Approach 1:
Complex perception and detection tasks are divided into separate modular pipelines, each handling specific functions (e.g., image processing, sensor fusion, object classification). This modular structure simplifies certification by allowing each module to be independently validated and tested.
Solution Approach 2:
Standardized interfaces and communication protocols are introduced between different processing modules, acting as intermediaries that simplify integration and verification. These standardized connections reduce the overall system complexity and make certification more manageable.
3Reliability
If redundant SoC arrangements with FuSa programs are implemented, then system reliability and ASIL ratings are improved, but device complexity and computational overhead increase
Solution Approach 1:
The functional safety verification functions are merged into the main processing pipelines rather than being completely separate systems. The FuSa programs execute alongside the primary processing tasks, sharing computational resources and reducing overall system complexity while maintaining safety assurance.
Solution Approach 2:
The redundant SoC arrangements are designed with multi-functional capabilities, where the same hardware resources can serve both primary processing functions and functional safety verification. This universal design reduces the need for completely separate dedicated safety hardware.
Data Source
AI summary
A sensor data input chiplet obtains sensor data from a sensor system. A central chiplet executes a functional safety program to dynamically compare and verify output of workloads being executed by a set of workload processing chiplets, where the workloads are executed across the set of workload processing chiplets based on the sensor data.


