Dual Micro-Processing Unit Architecture for Autonomous Vehicle Safety

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current safety microcontroller solutions for autonomous vehicles operate in a binary fashion, either allowing normal operation or shutting down the system upon detecting a malfunction, which is inadequate for advanced autonomous driving scenarios.

Innovation Solution

A vehicle system with a sensor distribution hub generating two data streams, where a primary micro-processing unit controls the vehicle using one stream and a secondary micro-processing unit, acting as a safety redundancy, takes over if the primary fails, ensuring continuous operation and safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single micro-processing unit is used for autonomous vehicle control, then device complexity is reduced, but reliability deteriorates because the system must shut down upon detecting any malfunction

Engineering Contradiction:
Improvesystem reliabilityVSAvoidmicro-processing architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the micro-processing system into two independent micro-processing units (primary and secondary), each capable of independently controlling the vehicle. This segmentation allows the system to avoid complete shutdown when one unit fails, as the other unit can continue operation, thereby improving reliability while maintaining manageable complexity through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the operational parameter from binary (normal/shutdown) to multi-state (normal, degraded, fallback) by implementing a dual-unit architecture with defined failover protocols. This allows the system to transition between different operational modes based on the state of each micro-processing unit, improving reliability without requiring complete system shutdown

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a dual micro-processing unit system is implemented for safety redundancy, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveautonomous driving safetyVSAvoidcontrol system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the primary and secondary micro-processing units into a unified control architecture where both units share common sensors, actuators, and communication interfaces. This merging approach improves reliability through redundancy while controlling overall system complexity by sharing common components rather than duplicating entire subsystems

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Both micro-processing units are designed with identical capabilities and can perform the same autonomous vehicle control functions. This universality allows either unit to take over completely if the other fails, improving reliability while using a standardized design that reduces overall system complexity through component commonality

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the system shuts down upon malfunction detection, then safety is maintained by preventing erroneous operations, but productivity deteriorates due to loss of continuous operation

Engineering Contradiction:
Improvesafe operationVSAvoidcontinuous driving capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary failover action where the secondary micro-processing unit is pre-configured and ready to immediately take control upon detecting primary unit failure. This preliminary preparation eliminates the need for system shutdown while maintaining safety, as the standby unit can seamlessly continue operation without interruption to vehicle control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a communication and coordination mechanism between the two micro-processing units that acts as an intermediary. This intermediary system monitors the state of both units and manages the failover process, allowing the system to transition from shutdown-based safety to continuous operation with safety monitoring, thereby improving productivity while maintaining reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10845803B2Method and apparatus for simultaneous processing and logging of automotive vision system with controls and fault monitoring
Publication Date: 2020.11.24 NIO TECH ANHUI CO LTD
  • US10845803B2 patent drawing
  • US10845803B2 patent drawing
  • US10845803B2 patent drawing

AI summary

According to one embodiment, an autonomous vehicle safety system can be implemented with a plurality of sensors, each of the plurality of sensors being configured to produce an electrical signal that is indicative of an environmental condition about a vehicle; a sensor distribution hub that receives the electrical signals from the plurality of sensors and generates two streams of data based on the electrical signals received from the plurality of sensors; a first micro-processing unit configured to receive a first of the two streams of data generated by the sensor distribution hub, where the first micro-processing unit is further configured to autonomously control the vehicle; and a second micro-processing unit configured to receive a second of the two streams of data generated by the sensor distribution hub, where the second micro-processing unit is also configured to autonomously control the vehicle.