Redundant Data Processing for Fault Recovery in Safety Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In safety-relevant systems, such as those for highly automated driving, existing technologies face challenges in ensuring continuous operation and data integrity during processor failures, as standard components lack effective mechanisms for redundant processing and data replication, leading to potential system failures and loss of functionality.

Innovation Solution

A system with multiple processing units that redundantly process data, where a restarted or reset unit independently requests and replicates data from other units, ensuring consistency checks and protected states to maintain system availability and safety, even in the absence of a processor component, using communication links and comparison units for error detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard Ethernet components and processing units are used in safety-relevant systems, then device complexity is reduced and ease of manufacture is improved, but system reliability deteriorates because self-tests cannot protect the entire system

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into multiple independent processing units (first processing unit, second processing unit) that each perform redundant calculations independently. This segmentation allows the system to maintain functionality even if one unit fails, improving reliability without requiring complete system redesign

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each processing unit is equipped with specific local capabilities: the first processing unit has a first interface for receiving data and a first calculation unit, while the second processing unit has a second interface and second calculation unit. This local quality differentiation enables independent operation and fault isolation

Inventive Principle:
Principle #3Local quality

2Reliability

If lockstep calculations are implemented for safety functions, then system reliability is improved through redundant processing, but device complexity increases due to multiple processing units and comparison mechanisms

Engineering Contradiction:
Improvesafety function reliabilityVSAvoidprocessing unit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple processing units (first and second processing units) into a single integrated system that performs lockstep calculations. The comparison unit merges the results from both units to verify consistency, achieving enhanced reliability through redundancy while maintaining a unified system architecture

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The second processing unit creates a copy of the calculation process performed by the first processing unit. Both units execute the same safety functions independently, and their results are compared to ensure correctness, implementing redundancy through copying rather than entirely separate systems

Inventive Principle:
Principle #26Copying

3Reliability

If distributed calculation is used for high safety and availability demands, then system reliability is improved through redundancy, but device complexity increases due to multiple separate hardware units

Engineering Contradiction:
ImproveavailabilityVSAvoidhardware unit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Both the first and second processing units are designed with universal functionality to perform the same safety-relevant calculations. Each unit has the capability to independently execute the full calculation sequence, allowing either unit to maintain system functionality and improving availability through redundant multi-functional units

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If a processing unit restarts or resets after an error, then system reliability is maintained through fault recovery, but loss of information occurs due to data lost or missed during restart

Engineering Contradiction:
Improvefault recovery capabilityVSAvoiddata loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The first interface acts as an intermediary that receives data and can supply it to the first processing unit even during restart conditions. The interface maintains data availability and manages the data flow between the external data source and the processing unit, preventing data loss during fault recovery operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10089195B2Method for redundant processing of data
Publication Date: 2018.10.02 ROBERT BOSCH GMBH
  • US10089195B2 patent drawing
  • US10089195B2 patent drawing
  • US10089195B2 patent drawing

AI summary

A method for redundant processing of data by at least two processing units is described. After a restart or reset, the first processing unit of the at least two processing units receives first portions of the data for processing from at least one second processing unit of the at least two processing units.