Fault-Tolerant Real-Time Computer System for Autonomous Vehicles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current real-time computer systems for autonomous devices, such as vehicles, face challenges in achieving the required reliability and safety due to software and hardware errors, which can lead to system failures, especially in safety-critical applications like autonomous driving, where achieving a mean time to failure (MTTF) of 10^9 hours is difficult even with rigorous development and testing.

Innovation Solution

A fault-tolerant real-time computer system design that includes non-secure and secure components, with a time server providing fault-tolerant global time, independent communication systems, and data processing components that can verify and calculate trajectories independently, ensuring that system failures do not lead to safety-critical events by separating the functions of trajectory calculation, verification, and decision-making.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If complex software components with millions of commands are used for autonomous control, then the system can perform sophisticated functions, but the reliability cannot achieve the required 10^-9 failures/hour due to software errors and hardware failures

Engineering Contradiction:
Improveautonomous control capabilityVSAvoidsystem reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into independent communication systems (first and second communication systems 110, 111) that are completely separate from each other. Each system processes data independently, and the segmentation allows fault isolation so that failures in one system do not propagate to the other, thereby maintaining reliability while supporting complex autonomous control functions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preemptive fault tolerance by duplicating critical components (two independent communication systems, multiple communication controllers per component) before failures can occur. This redundancy ensures that if one system fails, the other can take over, cushioning against reliability degradation while enabling sophisticated autonomous operations

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If hardware redundancy is increased to improve reliability, then system safety increases, but system costs increase

Engineering Contradiction:
Improvesystem safetyVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By segmenting the system into two independent communication systems rather than adding redundancy to a single system, the patent achieves fault tolerance through architectural separation. This segmentation allows cost-effective implementation because each independent system can use standard components, and the redundancy is achieved through system-level design rather than component-level multiplication

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality levels to different components: communication controllers are designed with high reliability (each having multiple independent communication interfaces), while other components can use standard configurations. This local differentiation of quality allows cost optimization by focusing redundancy where it is most critical for safety while reducing costs in less critical areas

Inventive Principle:
Principle #3Local quality

3Device complexity

If data processing components are connected through a single communication system, then the system structure is simplified, but a single point of failure can cause safety-critical events

Engineering Contradiction:
Improvesystem structureVSAvoidfault tolerance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the communication infrastructure into two completely independent communication systems (110, 111), each with separate communication controllers. Data processing components can connect to both systems, ensuring that a failure in one communication system does not create a single point of failure for the entire system, thereby maintaining fault tolerance without excessive structural complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The communication controllers act as intermediaries between data processing components and the communication systems. Each data processing component has multiple communication controllers that interface with both communication systems, providing a mediating layer that enables flexible connectivity while maintaining independence between the two communication systems and preventing single points of failure

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11936767B2Real-time computer system and method for controlling a system or a vehicle
Publication Date: 2024.03.19 TRUSTMOTION AUSTRIA GMBH
  • US11936767B2 patent drawing
  • US11936767B2 patent drawing
  • US11936767B2 patent drawing

AI summary

The invention relates to a real-time computer system for controlling a technical device, the real-time computer system comprising data acquisition components which are independent of each other, as well as non-secure data processing components for processing sensor data. A time server as well as a first communication system and a second communication system independent of it are provided, the time server periodically sending global time signals to the communication systems. Each data acquisition component has two communication controllers, wherein each data acquisition component is connected by two communication controllers via a communication line to the first communication system, and is connected by another communication controller to the second communication system via a communication line, such that each data acquisition component can transmit its sensor data to each of the two communication systems.