Fail-Operational Controller Software Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing fault-tolerant control systems are inefficient and costly due to the need for dedicated backup controllers with non-volatile memory, which requires additional hardware and resource usage.

Innovation Solution

Migrating software from non-volatile memory of a primary controller to random access memory of a backup controller, allowing the backup controller to temporarily function as a fail-operational controller, reducing the need for duplicate non-volatile memory and optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated backup controller with non-volatile memory is used to ensure fail-operational capability, then system reliability is improved, but device complexity and cost increase due to additional hardware and memory requirements

Engineering Contradiction:
Improvefail-operational capabilityVSAvoidcontroller architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The migrating controller is designed to serve dual purposes: it controls its own dedicated system while simultaneously serving as a backup controller for the primary controller when needed. This multi-functionality eliminates the need for a separate dedicated backup controller, reducing system complexity while maintaining fail-operational capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The backup controller functionality is merged with the migrating controller that already has its own control tasks. By combining these functions in a single controller, the patent reduces the total number of controllers needed in the system, thereby reducing device complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If a dedicated backup controller with non-volatile memory is used to ensure fail-operational capability, then system reliability is improved, but cost increases due to additional hardware and memory resources

Engineering Contradiction:
Improvefail-operational capabilityVSAvoidmemory resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The migrating controller's memory resources are utilized for dual purposes: storing software for its own control tasks and storing backup software from the primary controller. This shared memory usage eliminates the need for duplicate non-volatile memory in a separate backup controller, reducing overall memory requirements and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of maintaining identical copies of control software in separate non-volatile memory units, the patent copies the backup software to the migrating controller's memory. This approach reduces the total memory footprint by utilizing available memory resources in an existing controller rather than adding new memory hardware.

Inventive Principle:
Principle #26Copying

3Quantity of substance

If software code is migrated from non-volatile memory to random access memory of the backup controller, then non-volatile memory requirements are reduced, but the backup controller must temporarily allocate additional memory resources

Engineering Contradiction:
Improvenon-volatile memoryVSAvoidmemory resource usage
Core Design Contradiction:
Quantity of substanceVSUse of energy by moving object

Solution Approach 1:

The migrating controller dynamically adjusts its memory allocation based on operational needs. During normal operation, it uses its own software. When fail-operational mode is activated, it dynamically loads and executes backup software from the primary controller into its random access memory, optimizing memory usage based on the current system state.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameters of the migrating controller based on system needs. When a fault is detected in the primary controller, the migrating controller transitions from executing its own software to executing the migrated backup software, changing its functional parameters to maintain system operation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10324636B2Fail-operational system design pattern based on software code migration
Publication Date: 2019.06.18 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US10324636B2 patent drawing
  • US10324636B2 patent drawing
  • US10324636B2 patent drawing

AI summary

A fail-operational control system includes a migrating controller having a non-volatile memory, a RAM, and a CPU. The migrating controller includes software code stored in the non-volatile memory of the migrating controller. The software code stored in the non-volatile memory of the migrating controller executed by the CPU of the migrating controller is dedicated to a respective system. The respective system is not under the control of a primary controller from another system. In response to an enablement of a system operation of the primary controller of another system that requires a backup controller during execution of the system operation, fail-operational software code stored in the non-volatile memory of the primary controller of the other system is transferred to the RAM of the migrating controller. The migrating controller temporarily functions as a backup controller during the execution of the system operation in the primary controller of the other system.