Fault-Tolerant Architecture for Trajectory Planning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous moving entities face challenges in fail-safe trajectory planning due to potential hardware failures in computer-based systems, which can result in unsafe trajectories and false negatives, leading to collisions or unnecessary system failures.

Innovation Solution

A fault-tolerant system comprising a commander, monitor, and decision subsystems, where the monitor verifies trajectories within a safety envelope generated by the sensor fusion stage, ensuring only safe trajectories are executed, and additional mechanisms like information merging and agreement stages reduce the probability of false negatives by combining sensor data and using more capable computational resources for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fault-tolerant system with multiple subsystems (commander, monitor, decision) is implemented to verify trajectories, then the safety and reliability of trajectory planning is improved, but the device complexity increases

Engineering Contradiction:
Improvetrajectory safetyVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into three independent subsystems: commander (generates trajectories), monitor (verifies trajectories against safety envelope), and decision subsystem (selects final trajectory). This segmentation allows each component to have specialized, simplified functionality while collectively achieving high reliability through redundancy and cross-verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The monitor subsystem acts as an intermediary between the commander and decision subsystem. It generates a safety envelope from sensor data and verifies commander-generated trajectories against this envelope, preventing direct transmission of potentially faulty trajectories to the decision subsystem without verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the monitor subsystem performs trajectory verification using sensor fusion and safety envelope generation, then the probability of false negatives is reduced, but the computational resources and processing time increase

Engineering Contradiction:
Improvefalse negative rateVSAvoidverification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The monitor subsystem performs sensor fusion and generates the safety envelope in advance, before trajectory verification is needed. This preliminary action organizes the computational work ahead of time, allowing faster verification when trajectories need to be checked against the pre-computed safety envelope.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces complex real-time verification mechanics with a geometric approach: the safety envelope is computed as a geometric representation of safe space, and trajectory verification becomes a geometric containment check (is the trajectory inside the envelope?). This substitution simplifies the verification process while maintaining high reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If redundant sensor fusion stages in both commander and monitor are used, then the measurement precision and reliability of object detection is improved, but the use of energy and computational resources increases

Engineering Contradiction:
Improveobject detection accuracyVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Both the commander and monitor subsystems implement sensor fusion stages that process the same sensor data independently. This universal approach allows each subsystem to generate its own perception of the environment, enabling the commander to plan trajectories and the monitor to verify them against the same environmental model, improving reliability through independent verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3422131B1Method and fault tolerant computer architecture to improve the performance in fail-safe trajectory planning for a moving entity
Publication Date: 2020.06.03 TTTECH AUTO AG
  • EP3422131B1 patent drawingFigure 1~2
  • EP3422131B1 patent drawingFigure 3~4
  • EP3422131B1 patent drawingFigure 5

AI summary

The invention relates to a method and a fault-tolerant computer architecture to improve the performance in fail-safe trajectory planning for a moving entity. The method and FCTA uses a commander, that implements a sensor fusion stage and a trajectory planning stage, and a monitor that implements a sensor fusion stage, and a safe envelope generating stage. Sensors are monitoring the surrounding of the moving entity, and the sensor fusion stages accept sensor data as input. Based on said input the commander and the monitor produce as output real-time images of objects detected due to the monitoring of the one or more sensors. A trajectory planning stage of the commander generates trajectories based on said input, and the said safe envelope generating stage generates a safety envelope based said input. The commander provides the one or more trajectories to the monitor as well as to the decision subsystem.