Decision Subsystem Failover via Dual-Channel Actuator Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing control systems for fully autonomous technical systems, such as machines or vehicles, fail to ensure safe operation when the decision system experiences a fail-silent fault, leading to potential unsafe states.
Innovation Solution
The control system employs a decision system with fail-silent behavior, where if the decision system fails, the intelligent actuator receives setpoint values from the fallback system through a secondary input channel, ensuring the system transitions to a safe state by using a simple software executable on fault-detecting processors and highly reliable intelligent actuators with two independent input channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the decision system is implemented with a single input channel from the primary control system, then the device complexity is reduced, but the reliability deteriorates because the system cannot handle fail-silent faults in the decision system
Solution Approach 1:
The actuator is segmented into two independent input channels: a first input channel for receiving setpoint values from the primary control system through the decision system, and a second input channel for receiving setpoint values directly from the fallback system. This segmentation allows the system to maintain functionality even when the decision system fails, as the fallback system can directly control the actuator through the second input channel.
Solution Approach 2:
The fallback system acts as an intermediary that can bypass the decision system when it fails. By providing a direct communication path from the fallback system to the actuator through the second input channel, the intermediary mechanism ensures that safe state setpoint values can be transmitted even when the primary decision-making path is compromised.
2Reliability
If the system uses a complex fault-detection and failover mechanism with multiple independent subsystems, then the reliability improves, but the device complexity increases
Solution Approach 1:
The control system is segmented into four independent fault-containment units: primary control system, fallback system, monitoring system, and decision system. Each unit operates independently with its own computational resources and communication channels, limiting the propagation of faults while maintaining overall system functionality through the segmented architecture.
Solution Approach 2:
Each fault-containment unit is designed with local quality principles, where the fallback system specifically maintains the capability to calculate safe state setpoint values independently, and the actuator maintains independent input channels for different sources. This localized specialization ensures that each component has the specific quality needed to handle its designated function even when other components fail.
3Reliability
If the intelligent actuator always waits for commands from the decision system through the primary control system, then the device complexity is reduced, but the reliability deteriorates during decision system failures
Solution Approach 1:
The fallback system performs preliminary action by pre-calculating safe state setpoint values and making them available through the second input channel before the primary control path fails. This preliminary preparation ensures that when the decision system fails, the actuator can immediately switch to using pre-computed safe state commands without interruption or delay.
Solution Approach 2:
The actuator control logic is made dynamic by enabling switching between two different control paths: normally using the first input channel from the primary control system, but dynamically switching to the second input channel from the fallback system when a failure is detected. This dynamic adaptability allows the system to maintain operational continuity by adjusting the control path based on the operational state.
Data Source
AI summary
The invention is located in the field of computer technology and relates to a subsystem, the decision system, of a distributed fault-tolerant computer architecture for fully autonomous control of a technical system. A possible architecture of such a distributed fault-tolerant control system was published by H. Kopetz in the Springer Lecture Notes on Computer Science (LNCS) Vol. 13660, Chapter 4, pp. 61-84 under the title An Architecture for Safe Driving Automation in December 2022 [Kop22]. This safe control system consists of four subsystems, each of which is an independent hardware/software system and where each of the four subsystems forms a fault-containment unit. The four independent subsystems of the described architecture are a Primary Control System, a Monitoring System (MS), a Fallback System and a Decision System. Provided that the functioning of the decision system is always fault-free, the control system presented by H. Kopetz will bring the technical system to a safe state if an arbitrary (Byzantine) fault occurs in one of the other three subsystems. The present invention extends this architecture so that even in the event of a fail-silent fault of the decision system, the system is brought to a safe state.

