Cross-Connected Processor Redundancy for Transient Fault Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Autonomous vehicles face inefficiencies in handling transient faults, leading to excessive safety measures and inoperability due to lack of robust redundancy in safety-critical systems, with current failover units offering limited capabilities.
Innovation Solution
Implementing a robust fault-tolerant architecture with multiple processors and a cross-connector to reroute sensor inputs, allowing for efficient handling of transient faults and maintaining operation by isolating and confirming permanent faults.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If minimum failover units are used for redundancy, then device complexity is reduced, but reliability deteriorates due to limited fail-operational capabilities
Solution Approach 1:
The system divides processing functions into separate segments: a main processing unit handling primary operations and a safety processing unit handling safety-critical operations. This segmentation allows each unit to be optimized for its specific function while maintaining overall system reliability without excessive complexity.
Solution Approach 2:
A cross-connector acts as an intermediary component that enables communication and data transfer between the main processing unit and the safety processing unit. This mediator facilitates efficient failover capabilities while maintaining a relatively simple redundancy structure.
2Device complexity
If a main processing unit encompasses all available processing units, then device complexity is reduced, but reliability deteriorates as any fault renders the unit inoperable
Solution Approach 1:
The processing system is segmented into a main processing unit for general operations and a separate safety processing unit for safety-critical functions. This separation ensures that faults in the main unit do not necessarily compromise safety operations, improving fault tolerance while maintaining structural simplicity.
Solution Approach 2:
The system implements dynamic failover capabilities where the safety processing unit can take over operations from the main processing unit when faults are detected. This dynamic switching mechanism enhances reliability without requiring a permanently complex redundant structure.
3Reliability
If excessive safety actions are deployed for every temporary error, then reliability is improved, but productivity deteriorates as the autonomous vehicle becomes inoperable
Solution Approach 1:
The system applies different quality levels of safety response based on the nature and severity of detected faults. Transient faults trigger minimal or no safety actions, while permanent faults trigger appropriate safety protocols. This localized quality approach maintains vehicle operability for transient issues while ensuring safety for permanent faults.
Solution Approach 2:
The safety response mechanism is dynamic, adapting its level of intervention based on fault characteristics. The system can transition between normal operation, degraded operation, and safety shutdown states depending on the persistence and severity of detected faults, optimizing both reliability and productivity.
Data Source
AI summary
Provided are methods for robust fault tolerant architecture, which can include methods for determining transient faults and permanent faults. Some methods described also include applying one or more fault schemes, based on the determination of transient and permanent faults. Further provided are apparatuses for robust fault tolerant architecture, which can include apparatuses having a plurality of processors and cross connectors for determining fault states. Systems and computer program products are also provided.


