Dual Actuator Braking Fallback for Autonomous Vehicle Failures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle braking systems in autonomous or semi-autonomous vehicles lack sufficient redundancy and fail-safe mechanisms to ensure continued functionality in the event of errors, posing a risk of total failure and inability to safely transition control back to the driver.
Innovation Solution
A system unit comprising a first and second actuator system with auxiliary and emergency operating modes, allowing one actuator to take over functions of the other in case of errors, and an emergency mode to ensure minimal functionality even with dual failures, reducing reliance on external signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a primary and secondary actuator system are used with full functional redundancy, then system reliability is improved, but device complexity increases
Solution Approach 1:
The braking system is segmented into a primary actuator system and a secondary actuator system, each capable of independent operation. The primary system handles normal braking operations while the secondary system provides fallback capability, allowing the system to be divided into functional segments that can operate independently to maintain reliability without requiring a completely redundant third system.
Solution Approach 2:
The secondary actuator system is designed to provide partial functionality rather than complete redundancy. It can handle essential braking functions when the primary system fails, providing sufficient action for safe vehicle stoppage without requiring the full operational capability of a third completely redundant system, thus reducing overall complexity.
2Reliability
If all active controllers are designed for optimal response to every possible error combination, then system safety is improved, but software development complexity increases
Solution Approach 1:
Error recognition mechanisms are implemented in advance within each actuator system to detect failures before they compromise safety. The system proactively identifies errors and transitions between operational modes (normal, fallback, emergency) rather than requiring complex real-time analysis of all possible error combinations, reducing software complexity while maintaining safety.
Solution Approach 2:
Each actuator system includes feedback mechanisms that continuously monitor system state and error conditions. This feedback allows the control system to automatically respond to errors and switch between operational modes based on actual system conditions rather than requiring pre-programmed responses to all conceivable error scenarios, simplifying software development.
3Device complexity
If the secondary actuator system provides only limited fallback functionality, then device complexity is reduced, but system reliability deteriorates
Solution Approach 1:
The secondary actuator system is designed with dynamic adaptability, allowing it to provide enhanced functionality when needed. Rather than being statically limited, the secondary system can activate additional capabilities in response to primary system failures, ensuring sufficient braking performance for safe vehicle operation while maintaining simpler architecture during normal operation.
Solution Approach 2:
The system allows parameter changes in the secondary actuator's operational characteristics based on system needs. When the primary system is functional, the secondary operates in a reduced mode; when the primary fails, the secondary can transition to enhanced operational parameters to provide adequate braking capability, balancing complexity and reliability.
Data Source
AI summary
A system unit for an at least semi-automated mobile platform. The system unit includes at least one first actuator system and one second actuator system, which each include at least one auxiliary operating mode and one emergency operating mode. The first actuator system and the second actuator system are each configured and coupled: to switch into an inactive operating mode when a critical error is identified in the respective actuator system; and to switch into an auxiliary operating mode when one of the actuator systems switches into the inactive operating mode to additionally carry out at least portions of a functionality of the respective actuator system, which is in the inactive operating mode; and to switch into an emergency operating mode when a critical error is identified in the respective actuator system in the auxiliary operating mode.

