Dual Controller Node Architecture for Fault-Tolerant Automotive Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electromechanical brake systems in vehicles require significant redundancies and backups to maintain functionality when a node becomes faulty, which can be cost-prohibitive, especially for systems like automotive control systems that need a fault-tolerant architecture to continue operating without reduced performance.

Innovation Solution

A fault-tolerant node architecture is implemented, featuring a dual microcontroller configuration with a main controller and a supervisory controller, where the supervisory controller takes over if the main controller provides improper data, ensuring continuous operation by monitoring and validating data flows and overriding the main controller when necessary, utilizing a bus for communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If three controllers are provided at each node to provide sufficient redundancy for fault tolerance, then system reliability is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improvefault toleranceVSAvoidnumber of controllers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The node is segmented into two functional controllers: a main controller that handles normal operations and a supervisory controller that monitors and takes over when faults are detected. This segmentation provides fault tolerance without requiring three full controllers at each node, reducing complexity while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The supervisory controller acts as an intermediary that monitors the main controller's outputs and can intervene when faults are detected. This intermediary mechanism enables fault detection and takeover without requiring redundant full-function controllers, resolving the contradiction between reliability and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redundancy and backup systems are implemented to maintain functionality when a node fails, then system reliability is improved, but manufacturing cost increases

Engineering Contradiction:
Improvefault toleranceVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The supervisory controller is designed with multi-functionality, serving both as a monitor during normal operations and as a takeover controller when faults occur. This universal design reduces the need for separate dedicated backup systems, lowering manufacturing costs while maintaining fault tolerance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service fault tolerance through the supervisory controller that automatically detects faults and takes over control without requiring external intervention or complex backup systems. This self-service approach reduces manufacturing costs by eliminating the need for elaborate redundant hardware.

Inventive Principle:
Principle #25Self-service

3Reliability

If a fail-safe or fail-silent architecture is used where the system continues to function at reduced performance when a node fails, then system reliability is improved, but performance is reduced

Engineering Contradiction:
Improvecontinuous operationVSAvoidperformance level
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The supervisory controller is prepared in advance with the capability to take over control when the main controller fails. This preliminary preparation enables seamless transition without performance degradation, as the supervisory controller is already configured and ready to maintain full system functionality rather than operating at reduced performance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7620465B2Fault-tolerant node architecture for distributed systems
Publication Date: 2009.11.17 BWI CO LTD SA
  • US7620465B2 patent drawing
  • US7620465B2 patent drawing
  • US7620465B2 patent drawing

AI summary

A distributed architecture system including a plurality of nodes operatively coupled together by a bus. Each node includes a main controller configured to provide data to the bus and to an actuator, and a supervisory controller configured to provide data to the bus and to the actuator. Each node is configured such that during normal operations the main controller provides data to the actuator that controls the actuator and the supervisory controller generally does not provide data to the actuator that controls the actuator. Each node is configured such that if it is determined that the main controller is providing improper data, the supervisory controller provides data to the actuator that controls the actuator and the main controller does not provide data to the actuator that controls the actuator.