Conditional Automation Architecture Redundant Braking Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current conditional automation systems for level 3 vehicles, as defined by SAE or NHTSA standards, face legal and safety challenges due to the requirement for the driver to maintain control at all times, particularly in scenarios where system failures occur, necessitating a cost-effective architecture for ensuring safe return to driver supervision and emergency vehicle control.
Innovation Solution
A cost-effective architecture for a conditional automation driving assistance system includes a main computer receiving sensor data through a first communication network and transmitting commands to engine, braking, and steering control systems, with a backup computer and power source for redundancy, where the backup computer is only connected to the braking system for command transmission and the backup power source is shared with the main and backup computers, reducing redundant components while maintaining safety.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full redundancy is implemented with separate power sources and communication networks for backup computer, then system reliability is improved, but device complexity and cost increase
Solution Approach 1:
The patent merges the power supply architecture by connecting the backup power source to multiple computers (main computer, backup computer, and braking system computer) through a common power distribution network. This consolidation reduces the number of separate power pathways while maintaining redundancy, thereby lowering device complexity without compromising reliability.
Solution Approach 2:
The backup power source is designed with universal connectivity, serving multiple functions by powering different computers depending on failure scenarios. The same backup power source can support the backup computer during main computer failure or directly power the braking system computer during communication network failure, eliminating the need for dedicated power sources for each scenario.
2Reliability
If complete communication network redundancy is implemented with separate networks for main and backup computers, then system reliability is improved, but device complexity and cost increase
Solution Approach 1:
The braking system computer serves as an intermediary node that can receive commands directly from the backup computer through a simplified communication path. This mediator approach allows the backup computer to bypass the main communication network infrastructure and directly interface with the braking system, reducing communication complexity while ensuring reliability for critical emergency stop functions.
3Ease of manufacture
If redundant components are reduced to lower cost, then manufacturing cost is improved, but system reliability deteriorates
Solution Approach 1:
The system implements dynamic reconfiguration of power and communication pathways based on operational status. During normal operation, the main computer and its dedicated network are used. Upon detecting main computer failure, the system dynamically switches to alternative pathways where the backup computer communicates directly with the braking system computer, maintaining reliability while using fewer physical redundant components.
Solution Approach 2:
The patent changes the operational parameters of the communication network by allowing the backup computer to access the braking system computer through alternative communication interfaces or protocols when the main network fails. This parameter flexibility enables the system to maintain functionality with reduced hardware redundancy, lowering manufacturing costs while preserving reliability.
Data Source
Figure 1~2
AI summary
The invention concerns an architecture for a driving assistance system with conditional automation capable of controlling an automatic emergency stop of a vehicle, comprising: a set (2) of sensors of at least three different technologies for observing an area in front of a vehicle; a main computer (10) capable of receiving, via a first upstream data communication network, information from said set (2) of sensors, and of transmitting commands, via a first downstream communication network, to a first computer (3) of an engine control system, to a second computer (4) of a braking system and to a third computer (5) of a steering control system; a backup computer (11) capable of receiving, via a second upstream data communication network, information from said set of sensors in case of a failure relative to the main computer (10); a main power supply source linked to each computer; and a backup power supply source. The architecture comprises a second downstream communication network connecting only the backup computer (11) to said second computer (4) of the braking system for the transmission of commands, and the backup power supply source is connected only to the main computer (10), to the backup computer (11) and to the second computer (4) of the braking system.