Fault-Tolerant Computer System for Autonomous Driving Trajectories
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current advanced driver assistance systems (ADAS) and autonomous driving (AD) systems face challenges in designing fault-tolerant systems that ensure safe vehicle trajectories, particularly due to potential hardware or software failures, which could lead to unsafe conditions on the road, and lack clear guidelines for assigning Automotive Safety Integrity Levels (ASIL) to system components, hindering certification and series production.
Innovation Solution
A fault-tolerant computer system comprising a sensor part, primary part, secondary part, and tertiary part, with specific ASIL level assignments for each component (sensor part: QM/ASIL A/ASIL B, primary part: QM/ASIL A/ASIL B, secondary part: ASIL B/ASIL C/ASIL D, and tertiary part: ASIL B/ASIL C/ASIL D) to ensure safe trajectory generation and tolerance of system failures, enabling certification under the ISO 26262 standard.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a fault-tolerant system with multiple parts (primary, secondary, tertiary) is implemented to ensure safe trajectory generation, then the reliability and safety of the autonomous driving system is improved, but the device complexity and cost increase
Solution Approach 1:
The system is divided into distinct functional parts (sensor part, primary part, secondary part, tertiary part, decide part) with specific ASIL level assignments. Each part operates independently with defined safety functions, allowing the complex safety requirements to be distributed across manageable segments rather than requiring all components to meet the highest safety level simultaneously.
Solution Approach 2:
The patent introduces a new dimension of safety assurance through hierarchical ASIL level assignment across different system parts. Instead of uniform high-level safety requirements across all components, the system uses multiple ASIL levels (QM, ASIL A, ASIL B, ASIL C, ASIL D) to create a layered safety architecture where critical parts receive higher safety certification levels.
2Reliability
If all parts of the ADAS/AD system are designed to ASIL D level, then the safety and reliability is maximized, but the manufacturing cost and complexity increase significantly
Solution Approach 1:
Different parts of the system are assigned different ASIL levels based on their specific safety-criticality. The sensor part and primary part can operate at lower ASIL levels (QM, ASIL A, or ASIL B), while the secondary part and tertiary part are assigned ASIL B, C, or D levels. This localized quality approach ensures that only the most critical components receive the highest safety certification, reducing overall manufacturing costs while maintaining adequate safety.
3Reliability
If the secondary part and tertiary part perform correctness checks on trajectories, then the safety of the system is improved by detecting unsafe trajectories, but the processing time and computational load increase
Solution Approach 1:
The secondary part and tertiary part perform preliminary correctness checks on trajectories before they are executed by the vehicle. By verifying trajectory safety in advance using safe space estimates and correctness criteria, the system prevents unsafe trajectories from being implemented, thereby avoiding the need for time-consuming emergency corrections later while maintaining high safety standards.
Data Source
AI summary
A fault-tolerant computer system (FTCS) for generating safe trajectories for a vehicle. The FTCS includes: a sensor part (SENSE), a primary part (PRIM), a secondary part (SEC), a tertiary part (TER), and a decide part (DECIDE). The PRIM and TER are configured to produce trajectories by interpreting information of the real world as perceived by the SENSE. The SEC is configured to produce a safe space estimate (FSE) by interpreting information of the real world as perceived by SENSE. The DECIDE and/or SEC are configured to execute correctness checks that take trajectories and FSE as inputs, and qualify a trajectory (TRJ) as safe when said TRJ is inside the FSE, and qualify a trajectory (UTRJ) as unsafe when said UTRJ is not inside the FSE.


