Conditional Redundancy Verification for Control Device Safety

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing control units in safety-critical systems, such as motor vehicles, are resource-intensive and inefficient due to the need for redundant calculations across their entire runtime, leading to increased costs, heat dissipation, and reduced performance, especially in image-processing applications.

Innovation Solution

Implement a method where redundant calculations are limited to only safety-critical output data, with a second determination triggered only when the initial data indicates a potential intervention, using either the same or different algorithms and hardware, to verify the accuracy of safety-critical output data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundant calculations are performed across the entire runtime of the control unit, then safety-critical functions are secured, but computing power and energy consumption increase significantly

Engineering Contradiction:
Improvesafety-critical function securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies dynamics by making the redundancy verification conditional rather than static. The control unit dynamically activates redundant calculations only when output data falls within a critical range that could lead to safety-critical interventions, and deactivates them when output data is outside this range. This dynamic adjustment resolves the contradiction by maintaining safety security only when necessary, thereby reducing overall energy consumption while preserving reliability for critical scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of verification frequency based on output data characteristics. By monitoring whether output data falls within a predefined critical range, the system adjusts the level of redundancy applied - full verification when critical, no verification when non-critical. This parameter-based approach allows the system to maintain high reliability when needed while minimizing energy consumption during normal operation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If redundant calculations are performed across the entire runtime of the control unit, then safety-critical functions are secured, but computing power requirements increase

Engineering Contradiction:
Improvesafety-critical function securityVSAvoidcomputing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The system dynamically adjusts computing power allocation by activating redundant calculation paths only when output data indicates a risk of safety-critical intervention. During normal operation, full computing power is not required for redundancy, allowing the control unit to operate with lower computing power requirements while maintaining the ability to provide full verification when safety concerns arise.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by adjusting the verification intensity based on the criticality of the current output state. When output data is outside the critical range, the system reduces computing power usage by skipping redundant calculations. When output data enters the critical range, the system increases computing power allocation to perform full redundant verification, thus resolving the contradiction between reliability and computing power requirements.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If redundant calculations are performed across the entire runtime of the control unit, then safety-critical functions are secured, but heat dissipation increases

Engineering Contradiction:
Improvesafety-critical function securityVSAvoidheat dissipation
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies dynamics to thermal management by conditionally activating heat-generating redundant calculations only when safety verification is actually needed. By monitoring output data against critical thresholds, the system minimizes the duration and frequency of high-power verification operations, thereby reducing overall heat dissipation while maintaining safety security for critical functions.

Inventive Principle:
Principle #15Dynamics

4Reliability

If redundant hardware components are added for safety verification, then safety-critical functions are secured, but device complexity and hardware requirements increase

Engineering Contradiction:
Improvesafety-critical function securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the control unit so that existing hardware components can serve multiple functions - both primary control operations and safety-critical verification. Rather than adding dedicated redundant hardware, the system uses the same processing units to perform both normal control tasks and conditional safety verification, thereby maintaining reliability without increasing hardware requirements or device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2693278B1Method for efficiently securing the safety-critical functions of a control device and control device
Publication Date: 2019.08.07 AUDI AG
  • EP2693278B1 patent drawingFigure 1
  • EP2693278B1 patent drawingFigure 2~3

AI summary

Method for operating a control unit (10) processing at least one input date to at least one output date by means of an algorithm (17), wherein a second determination of the output date is carried out only if an output date is contained in a first group that does not contain all possible output data, in order to check the output date.