Conditional Automation Architecture Redundant Braking Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current conditional automation systems for level 3 vehicles, as defined by SAE or NHTSA standards, face legal and safety challenges due to the requirement for the driver to maintain control at all times, particularly in scenarios where system failures occur, necessitating a cost-effective architecture for ensuring safe return to driver supervision and emergency vehicle control.

Innovation Solution

A cost-effective architecture for a conditional automation driving assistance system includes a main computer receiving sensor data through a first communication network and transmitting commands to engine, braking, and steering control systems, with a backup computer and power source for redundancy, where the backup computer is only connected to the braking system for command transmission and the backup power source is shared with the main and backup computers, reducing redundant components while maintaining safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full redundancy is implemented with separate power sources and communication networks for backup computer, then system reliability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the power supply architecture by connecting the backup power source to multiple computers (main computer, backup computer, and braking system computer) through a common power distribution network. This consolidation reduces the number of separate power pathways while maintaining redundancy, thereby lowering device complexity without compromising reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The backup power source is designed with universal connectivity, serving multiple functions by powering different computers depending on failure scenarios. The same backup power source can support the backup computer during main computer failure or directly power the braking system computer during communication network failure, eliminating the need for dedicated power sources for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If complete communication network redundancy is implemented with separate networks for main and backup computers, then system reliability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The braking system computer serves as an intermediary node that can receive commands directly from the backup computer through a simplified communication path. This mediator approach allows the backup computer to bypass the main communication network infrastructure and directly interface with the braking system, reducing communication complexity while ensuring reliability for critical emergency stop functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If redundant components are reduced to lower cost, then manufacturing cost is improved, but system reliability deteriorates

Engineering Contradiction:
Improvemanufacturing costVSAvoidsystem reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system implements dynamic reconfiguration of power and communication pathways based on operational status. During normal operation, the main computer and its dedicated network are used. Upon detecting main computer failure, the system dynamically switches to alternative pathways where the backup computer communicates directly with the braking system computer, maintaining reliability while using fewer physical redundant components.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the operational parameters of the communication network by allowing the backup computer to access the braking system computer through alternative communication interfaces or protocols when the main network fails. This parameter flexibility enables the system to maintain functionality with reduced hardware redundancy, lowering manufacturing costs while preserving reliability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3242823B1Architecture for a driving assistance system with conditional automation
Publication Date: 2018.10.03 VALEO SCHALTER & SENSOREN GMBH
  • EP3242823B1 patent drawingFigure 1~2

AI summary

The invention concerns an architecture for a driving assistance system with conditional automation capable of controlling an automatic emergency stop of a vehicle, comprising: a set (2) of sensors of at least three different technologies for observing an area in front of a vehicle; a main computer (10) capable of receiving, via a first upstream data communication network, information from said set (2) of sensors, and of transmitting commands, via a first downstream communication network, to a first computer (3) of an engine control system, to a second computer (4) of a braking system and to a third computer (5) of a steering control system; a backup computer (11) capable of receiving, via a second upstream data communication network, information from said set of sensors in case of a failure relative to the main computer (10); a main power supply source linked to each computer; and a backup power supply source. The architecture comprises a second downstream communication network connecting only the backup computer (11) to said second computer (4) of the braking system for the transmission of commands, and the backup power supply source is connected only to the main computer (10), to the backup computer (11) and to the second computer (4) of the braking system.