Diverse Software Control for Autonomous Vehicle Fault Tolerance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current autonomous vehicle systems face challenges in achieving fault-tolerant control, particularly at higher automation levels (Level 4 and Level 5), as they struggle to maintain safety due to hardware and software design errors, with complex software systems being difficult to validate thoroughly to meet the required error rates for ASIL D integrity levels.
Innovation Solution
The method involves identifying and separating Non-Deterministic Design Constructs (NDDCs) in the software system, executing simple software on fault-tolerant hardware to mask hardware failures, and using diverse versions of complex software on independent Fault Containment Units (FCUs) to increase reliability through comparison and decision-making by a simple software authority.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If complex software systems are used for autonomous vehicle control, then functionality and adaptability are improved, but validation thoroughness and reliability are worsened due to difficulty in achieving ASIL D error rates
Solution Approach 1:
The patent segments the software system into distinct functional modules that can be independently validated and tested. This modular approach allows thorough validation of each component while maintaining overall system complexity and functionality.
Solution Approach 2:
The patent employs model-based validation where virtual models and simulations are created to replicate real-world scenarios. These models allow extensive testing and validation without requiring physical prototypes, thereby improving validation thoroughness while maintaining system adaptability.
2Reliability
If hardware redundancy is implemented to mask hardware failures, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent extracts the redundancy function from the main control system and implements it as a separate validation layer. This allows fault tolerance to be added without significantly increasing the complexity of the core hardware architecture.
Solution Approach 2:
The patent designs the redundant hardware components to serve multiple functions - they can operate as primary components when functional and as backup components when needed. This multi-functionality reduces the need for dedicated redundant hardware, thereby limiting complexity increase.
3Reliability
If extensive testing and validation are performed to reduce design errors, then reliability is improved, but loss of time and productivity are worsened
Solution Approach 1:
The patent implements formal verification methods during the design and development phases to identify and correct errors before they reach the testing stage. This preliminary validation reduces the time required for extensive post-development testing while maintaining high reliability standards.
Solution Approach 2:
The patent replaces physical testing and validation with automated software-based verification and simulation systems. This substitution dramatically reduces validation time while maintaining or improving the thoroughness of error detection compared to traditional manual testing methods.
Data Source
Figure 1~2
Figure 3
AI summary
The present invention describes an innovative method for realizing a complex electronic system for controlling a safety-critical technical process, e.g., the guidance of an autonomous vehicle. A distinction is made between simple and complex software, wherein the simple software is executed on fault-tolerant hardware, and wherein several diverse versions of the complex software are executed simultaneously on independent Fault Containment Units (FCUs). From the results of the complex software, a decision instance, implemented using simple software, selects a result that is then forwarded to the actuators.