Multimodal Autonomous Control Arbitration for Degraded Vehicle States

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle automation systems are limited in safely controlling autonomous vehicles when one or more devices or processes associated with the vehicle are in a failed or degraded state, as they assume all components operate nominally.

Innovation Solution

A system that includes infrastructure sensing devices, autonomous health monitors, an autonomous state machine, and an arbiter of autonomous control instructions to assess the operating state of the vehicle and selectively enable only safe control instructions to driving components, allowing the vehicle to operate at a level of autonomy corresponding to its available capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the autonomous vehicle operates with multiple sensors, controllers, and health monitors to ensure safe operation, then the reliability of the system improves, but the device complexity increases

Engineering Contradiction:
Improvesafe operation under component failureVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The autonomous vehicle system is divided into multiple independent functional modules including distinct health monitors for different operational aspects, multiple autonomous controllers generating separate control instructions, and an arbiter that selectively enables control instructions. This segmentation allows the system to maintain reliability through modular redundancy while managing complexity through structured organization of components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An arbiter of autonomous control instructions is introduced as an intermediary component that receives control instructions from multiple autonomous controllers, evaluates them based on health monitor data, and selectively enables only safe control instructions to pass to driving components. This intermediary layer coordinates the interactions between numerous components, improving reliability while containing system complexity through centralized arbitration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the system assumes all devices and components operate nominally to simplify control logic, then the ease of operation improves, but the reliability deteriorates when components fail

Engineering Contradiction:
Improvecontrol logic simplicityVSAvoidoperation safety under component failure
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary health assessments through multiple distinct health monitors that continuously evaluate operational aspects before control instructions are executed. The arbiter pre-evaluates control instructions from multiple autonomous controllers based on health monitor data, enabling only safe instructions to pass to driving components. This preliminary action ensures reliability under component failure while maintaining relatively simple control logic through automated health-based arbitration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11847913B2Systems and methods for implementing multimodal safety operations with an autonomous agent
Publication Date: 2023.12.19 MAY MOBILITY INC
  • US11847913B2 patent drawing
  • US11847913B2 patent drawing
  • US11847913B2 patent drawing

AI summary

A system and method includes an autonomous agent having a communication interface that enables the autonomous agent to communicate with a plurality of infrastructure sensing devices; a plurality of distinct health monitors that monitor distinct operational aspects of the autonomous agent; an autonomous state machine that computes a plurality of allowed operating states of the autonomous agent based on inputs from the plurality of distinct health monitors; a plurality of distinct autonomous controllers that generate a plurality of distinct autonomous control instructions; and an arbiter of autonomous control instructions that: collects, as a first input, the plurality of autonomous control instructions generated by each of the plurality of distinct autonomous controllers; collects, as a second input, data relating to the plurality of allowed operating state of the autonomous agent; and selectively enables only a subset of the autonomous control instructions to pass to driving components of the autonomous agent.